diff --git a/bfx/hic-pro/trivy-scan-results.json b/bfx/hic-pro/trivy-scan-results.json new file mode 100644 index 00000000..58405602 --- /dev/null +++ b/bfx/hic-pro/trivy-scan-results.json @@ -0,0 +1,3907 @@ +{ + "tool": "hic-pro", + "scan_timestamp": "2026-08-16T17:05:52Z", + "workflow_run_id": "31960542324", + "versions": { + "3.1.0": { + "image": "ghcr.io/bundlecore/products/bfx/hic-pro:3.1.0", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2021-34552", + "VendorIDs": [ + "GHSA-7534-mm45-c74v" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "8.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-34552", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3ffbdb02c5b4abc47076e64a4a0513bfd8c97650b305c4d447cedf3126344f85", + "Title": "python-pillow: Buffer overflow in image convert function", + "Description": "Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "ghsa": 4, + "nvd": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.8, + "V40Score": 9.3 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-34552.json", + "https://access.redhat.com/security/cve/CVE-2021-34552", + "https://github.com/advisories/GHSA-7534-mm45-c74v", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-331.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/31c473898c29d1b7cb6555ce67d9503a4906b83f", + "https://github.com/python-pillow/Pillow/pull/5567", + "https://lists.debian.org/debian-lts-announce/2021/07/msg00018.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7V6LCG525ARIX6LX5QRYNAWVDD2MD2SV", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7V6LCG525ARIX6LX5QRYNAWVDD2MD2SV/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUGBBT63VL7G4JNOEIPDJIOC34ZFBKNJ", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUGBBT63VL7G4JNOEIPDJIOC34ZFBKNJ/", + "https://nvd.nist.gov/vuln/detail/CVE-2021-34552", + "https://pillow.readthedocs.io/en/stable/releasenotes/8.3.0.html#buffer-overflow", + "https://pillow.readthedocs.io/en/stable/releasenotes/index.html", + "https://security.gentoo.org/glsa/202211-10", + "https://ubuntu.com/security/notices/USN-5227-1", + "https://ubuntu.com/security/notices/USN-5227-2", + "https://www.cve.org/CVERecord?id=CVE-2021-34552" + ], + "PublishedDate": "2021-07-13T17:15:09.4Z", + "LastModifiedDate": "2026-06-17T03:56:06.653Z" + }, + { + "VulnerabilityID": "CVE-2022-22817", + "VendorIDs": [ + "GHSA-8vj2-vxx3-667w" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "9.0.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-22817", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:385c23e9b1512d777bc07b98cb6ec41bdd0f2dfe5a99e5df43b7c2aad0701167", + "Title": "python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions", + "Description": "PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.", + "Severity": "CRITICAL", + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 4, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.8, + "V40Score": 9.3 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-22817", + "https://bugzilla.redhat.com/show_bug.cgi?id=2042522", + "https://bugzilla.redhat.com/show_bug.cgi?id=2042527", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22815", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22816", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22817", + "https://errata.almalinux.org/8/ALSA-2022-0643.html", + "https://errata.rockylinux.org/RLSA-2022:0643", + "https://github.com/advisories/GHSA-8vj2-vxx3-667w", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2022-10.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/8531b01d6cdf0b70f256f93092caa2a5d91afc11", + "https://linux.oracle.com/cve/CVE-2022-22817.html", + "https://linux.oracle.com/errata/ELSA-2022-0643.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00018.html", + "https://lists.debian.org/debian-lts-announce/2024/03/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-22817", + "https://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#fixed-imagepath-path-array-handling", + "https://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#restrict-builtins-available-to-imagemath-eval", + "https://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html#security", + "https://security.gentoo.org/glsa/202211-10", + "https://ubuntu.com/security/notices/USN-5227-1", + "https://ubuntu.com/security/notices/USN-5227-2", + "https://ubuntu.com/security/notices/USN-5227-3", + "https://www.cve.org/CVERecord?id=CVE-2022-22817", + "https://www.debian.org/security/2022/dsa-5053" + ], + "PublishedDate": "2022-01-10T14:12:55.16Z", + "LastModifiedDate": "2026-06-17T04:29:05.48Z" + }, + { + "VulnerabilityID": "CVE-2023-50447", + "VendorIDs": [ + "GHSA-3f63-hfp8-52jq" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "10.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-50447", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:6b8c9db402aa5e6c6961288aa826ea01fdb912868f80ddff5314264f4856d0b2", + "Title": "pillow: Arbitrary Code Execution via the environment parameter", + "Description": "Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-94", + "CWE-95" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 4, + "nvd": 3, + "oracle-oval": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 8.1, + "V40Score": 9.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2024/01/20/1", + "https://access.redhat.com/errata/RHSA-2024:0893", + "https://access.redhat.com/security/cve/CVE-2023-50447", + "https://bugzilla.redhat.com/2259479", + "https://devhub.checkmarx.com/cve-details/CVE-2023-50447", + "https://devhub.checkmarx.com/cve-details/CVE-2023-50447/", + "https://duartecsantos.github.io/2023-01-02-CVE-2023-50447", + "https://duartecsantos.github.io/2023-01-02-CVE-2023-50447/", + "https://duartecsantos.github.io/2024-01-02-CVE-2023-50447", + "https://duartecsantos.github.io/2024-01-02-CVE-2023-50447/", + "https://errata.almalinux.org/8/ALSA-2024-0893.html", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/45c726fd4daa63236a8f3653530f297dc87b160a", + "https://github.com/python-pillow/Pillow/releases", + "https://linux.oracle.com/cve/CVE-2023-50447.html", + "https://linux.oracle.com/errata/ELSA-2024-0893.html", + "https://lists.debian.org/debian-lts-announce/2024/01/msg00019.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-50447", + "https://pillow.readthedocs.io/en/stable/releasenotes/10.2.0.html#imagemath-eval-restricted-environment-keys", + "https://pillow.readthedocs.io/en/stable/releasenotes/10.2.0.html#security", + "https://ubuntu.com/security/notices/USN-6618-1", + "https://ubuntu.com/security/notices/USN-8135-1", + "https://www.cve.org/CVERecord?id=CVE-2023-50447" + ], + "PublishedDate": "2024-01-19T20:15:11.87Z", + "LastModifiedDate": "2026-06-17T06:39:39.007Z" + }, + { + "VulnerabilityID": "CVE-2021-23437", + "VendorIDs": [ + "GHSA-98vv-pw6r-q6q4" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "8.3.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-23437", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:bd19a035478dd5c2f31e6ec7febefbf392c0e187c11891edcc50ca27efaf236d", + "Title": "python-pillow: possible ReDoS via the getrgb function", + "Description": "The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 1 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2021-23437", + "https://github.com/advisories/GHSA-98vv-pw6r-q6q4", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-317.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b", + "https://lists.debian.org/debian-lts-announce/2024/03/msg00021.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RNSG6VFXTAROGF7ACYLMAZNQV4EJ6I2C/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKRCL7KKAKOXCVD7M6WC5OKFGL4L3SJT/", + "https://nvd.nist.gov/vuln/detail/CVE-2021-23437", + "https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html", + "https://security.gentoo.org/glsa/202211-10", + "https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443", + "https://ubuntu.com/security/notices/USN-5227-1", + "https://ubuntu.com/security/notices/USN-5227-2", + "https://www.cve.org/CVERecord?id=CVE-2021-23437" + ], + "PublishedDate": "2021-09-03T16:15:08.317Z", + "LastModifiedDate": "2026-06-17T03:38:45.71Z" + }, + { + "VulnerabilityID": "CVE-2022-24303", + "VendorIDs": [ + "GHSA-9j59-75qj-795w" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "9.0.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-24303", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:38e32f1a7211b5c62f76b7d79f16eb391a3fa94b845e5c027a03b6360eb845b3", + "Title": "python-pillow: temporary directory with a space character allows removal of unrelated file after im.show() and related actions", + "Description": "Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.", + "Severity": "HIGH", + "VendorSeverity": { + "bitnami": 4, + "ghsa": 3, + "nvd": 4, + "redhat": 2, + "ubuntu": 1 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V3Score": 9.1 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.1, + "V40Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V2Score": 6.4, + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-24303", + "https://github.com/advisories/GHSA-9j59-75qj-795w", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2022-168.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/e8ab5640774716c5486d3cb05167f74f742ad6ef/CHANGES.rst?plain=1#L1172", + "https://github.com/python-pillow/Pillow/commit/10c4f75aaa383bd9671e923e3b91d391ea12d781", + "https://github.com/python-pillow/Pillow/commit/143032103c9f2d55a0a7960bd3e630cb72549e8a", + "https://github.com/python-pillow/Pillow/commit/427221ef5f19157001bf8b1ad7cfe0b905ca8c26", + "https://github.com/python-pillow/Pillow/pull/3450", + "https://github.com/python-pillow/Pillow/pull/6010", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W4ZUXPKEX72O3E5IHBPVY5ZCPMJ4GHHV", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W4ZUXPKEX72O3E5IHBPVY5ZCPMJ4GHHV/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XR6UP2XONXOVXI4446VY72R63YRO2YTP", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XR6UP2XONXOVXI4446VY72R63YRO2YTP/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-24303", + "https://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html", + "https://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html#security", + "https://security.gentoo.org/glsa/202211-10", + "https://ubuntu.com/security/notices/USN-5777-1", + "https://ubuntu.com/security/notices/USN-5777-2", + "https://www.cve.org/CVERecord?id=CVE-2022-24303" + ], + "PublishedDate": "2022-03-28T02:15:07.14Z", + "LastModifiedDate": "2026-06-17T04:31:35.093Z" + }, + { + "VulnerabilityID": "CVE-2022-45198", + "VendorIDs": [ + "GHSA-m2vv-5vj5-2hm7" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "9.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-45198", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:37859d98f7facbc6ac5fbe55e46e79b05fc8d62d0769d8e5fbfdab5c1f3bd9a0", + "Title": "Pillow before 9.2.0 performs Improper Handling of Highly Compressed GI ...", + "Description": "Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "ubuntu": 1 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://bugs.gentoo.org/855683", + "https://cwe.mitre.org/data/definitions/409.html", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2022-42979.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/11918eac0628ec8ac0812670d9838361ead2d6a4", + "https://github.com/python-pillow/Pillow/pull/6402", + "https://github.com/python-pillow/Pillow/pull/6402/commits/c9f1b35e981075110a23487a8d4a6cbb59a588ea", + "https://github.com/python-pillow/Pillow/releases/tag/9.2.0", + "https://nvd.nist.gov/vuln/detail/CVE-2022-45198", + "https://security.gentoo.org/glsa/202211-10", + "https://ubuntu.com/security/notices/USN-5777-1", + "https://ubuntu.com/security/notices/USN-5777-2", + "https://www.cve.org/CVERecord?id=CVE-2022-45198" + ], + "PublishedDate": "2022-11-14T07:15:10.347Z", + "LastModifiedDate": "2026-06-17T05:09:37.82Z" + }, + { + "VulnerabilityID": "CVE-2023-44271", + "VendorIDs": [ + "GHSA-8ghj-p4vj-mr35" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "10.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-44271", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f3bc3f13269122010499951f2c4b907b0210fcfe2745f706f54e68a462ac0fbb", + "Title": "python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument", + "Description": "An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:3005", + "https://access.redhat.com/security/cve/CVE-2023-44271", + "https://bugzilla.redhat.com/2247820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2247820", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44271", + "https://devhub.checkmarx.com/cve-details/CVE-2023-44271", + "https://devhub.checkmarx.com/cve-details/CVE-2023-44271/", + "https://errata.almalinux.org/8/ALSA-2024-3005.html", + "https://errata.rockylinux.org/RLSA-2024:3005", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2023-227.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/1fe1bb49c452b0318cad12ea9d97c3bef188e9a7", + "https://github.com/python-pillow/Pillow/pull/7244", + "https://linux.oracle.com/cve/CVE-2023-44271.html", + "https://linux.oracle.com/errata/ELSA-2024-3005.html", + "https://lists.debian.org/debian-lts-announce/2024/03/msg00021.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N2JOEDUJDQLCUII2LQYZYSM7RJL2I3P4", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N2JOEDUJDQLCUII2LQYZYSM7RJL2I3P4/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-44271", + "https://ubuntu.com/security/notices/USN-6618-1", + "https://ubuntu.com/security/notices/USN-8135-1", + "https://www.cve.org/CVERecord?id=CVE-2023-44271" + ], + "PublishedDate": "2023-11-03T05:15:30.137Z", + "LastModifiedDate": "2026-06-17T06:27:15.85Z" + }, + { + "VulnerabilityID": "CVE-2023-4863", + "VendorIDs": [ + "GHSA-j7hp-h8jx-5ppr" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "10.0.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-4863", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:5129c7f0f261c426034130cd954fc3a1c1cdfb6cf815d3610ba366a77e239847", + "Title": "libwebp: Heap buffer overflow in WebP Codec", + "Description": "Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "cbl-mariner": 3, + "ghsa": 3, + "julia": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 9.6 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2023/09/21/4", + "http://www.openwall.com/lists/oss-security/2023/09/22/1", + "http://www.openwall.com/lists/oss-security/2023/09/22/3", + "http://www.openwall.com/lists/oss-security/2023/09/22/4", + "http://www.openwall.com/lists/oss-security/2023/09/22/5", + "http://www.openwall.com/lists/oss-security/2023/09/22/6", + "http://www.openwall.com/lists/oss-security/2023/09/22/7", + "http://www.openwall.com/lists/oss-security/2023/09/22/8", + "http://www.openwall.com/lists/oss-security/2023/09/26/1", + "http://www.openwall.com/lists/oss-security/2023/09/26/7", + "http://www.openwall.com/lists/oss-security/2023/09/28/1", + "http://www.openwall.com/lists/oss-security/2023/09/28/2", + "http://www.openwall.com/lists/oss-security/2023/09/28/4", + "https://access.redhat.com/errata/RHSA-2023:5214", + "https://access.redhat.com/errata/RHSA-2023:5224", + "https://access.redhat.com/security/cve/CVE-2023-4863", + "https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway", + "https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/", + "https://blog.isosceles.com/the-webp-0day", + "https://blog.isosceles.com/the-webp-0day/", + "https://bugzilla.redhat.com/2238431", + "https://bugzilla.redhat.com/show_bug.cgi?id=2238431", + "https://bugzilla.suse.com/show_bug.cgi?id=1215231", + "https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html", + "https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html", + "https://chromium.googlesource.com/webm/libwebp.git/+/902bc9190331343b2017211debcec8d2ab87e17a", + "https://crbug.com/1479274", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4863", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5129", + "https://en.bandisoft.com/honeyview/history", + "https://en.bandisoft.com/honeyview/history/", + "https://errata.almalinux.org/9/ALSA-2023-5224.html", + "https://errata.rockylinux.org/RLSA-2023:5214", + "https://github.com/ImageMagick/ImageMagick/discussions/6664", + "https://github.com/dlemstra/Magick.NET/releases/tag/13.3.0", + "https://github.com/electron/electron/pull/39823", + "https://github.com/electron/electron/pull/39825", + "https://github.com/electron/electron/pull/39826", + "https://github.com/electron/electron/pull/39827", + "https://github.com/electron/electron/pull/39828", + "https://github.com/jaredforth/webp/commit/9d4c56e63abecc777df71c702503c3eaabd7dcbc", + "https://github.com/jaredforth/webp/pull/30", + "https://github.com/python-pillow/Pillow/pull/7395", + "https://github.com/qnighy/libwebp-sys2-rs/commit/4560c473a76ec8bd8c650f19ddf9d7a44f719f8b", + "https://github.com/qnighy/libwebp-sys2-rs/pull/21", + "https://github.com/webmproject/libwebp", + "https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a", + "https://github.com/webmproject/libwebp/releases/tag/v1.3.2", + "https://linux.oracle.com/cve/CVE-2023-4863.html", + "https://linux.oracle.com/errata/ELSA-2023-5309.html", + "https://lists.debian.org/debian-lts-announce/2023/09/msg00015.html", + "https://lists.debian.org/debian-lts-announce/2023/09/msg00016.html", + "https://lists.debian.org/debian-lts-announce/2023/09/msg00017.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/", + "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863", + "https://news.ycombinator.com/item?id=37478403", + "https://nvd.nist.gov/vuln/detail/CVE-2023-4863", + "https://pillow.readthedocs.io/en/stable/releasenotes/10.0.1.html#security", + "https://rustsec.org/advisories/RUSTSEC-2023-0060.html", + "https://rustsec.org/advisories/RUSTSEC-2023-0061.html", + "https://security-tracker.debian.org/tracker/CVE-2023-4863", + "https://security.gentoo.org/glsa/202309-05", + "https://security.gentoo.org/glsa/202401-10", + "https://security.netapp.com/advisory/ntap-20230929-0011", + "https://security.netapp.com/advisory/ntap-20230929-0011/", + "https://sethmlarson.dev/security-developer-in-residence-weekly-report-16", + "https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863", + "https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/", + "https://ubuntu.com/security/notices/USN-6367-1", + "https://ubuntu.com/security/notices/USN-6368-1", + "https://ubuntu.com/security/notices/USN-6369-1", + "https://ubuntu.com/security/notices/USN-6369-2", + "https://www.bentley.com/advisories/be-2023-0001", + "https://www.bentley.com/advisories/be-2023-0001/", + "https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks", + "https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/", + "https://www.cisa.gov/known-exploited-vulnerabilities-catalog", + "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4863", + "https://www.cve.org/CVERecord?id=CVE-2023-4863", + "https://www.debian.org/security/2023/dsa-5496", + "https://www.debian.org/security/2023/dsa-5497", + "https://www.debian.org/security/2023/dsa-5498", + "https://www.mozilla.org/en-US/security/advisories/mfsa2023-40", + "https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/", + "https://www.vicarius.io/vsociety/posts/zero-day-webp-vulnerability-cve-2023-4863" + ], + "PublishedDate": "2023-09-12T15:15:24.327Z", + "LastModifiedDate": "2026-06-17T06:38:46.547Z" + }, + { + "VulnerabilityID": "CVE-2024-28219", + "VendorIDs": [ + "GHSA-44wm-f244-xhp3" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "10.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-28219", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:6cba8a6d90ffc92724e8b347b19a2efa351cf9c039025a17f137cfefecd521f6", + "Title": "python-pillow: buffer overflow in _imagingcms.c", + "Description": "In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-680" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "bitnami": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 6.7, + "V40Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:4227", + "https://access.redhat.com/security/cve/CVE-2024-28219", + "https://bugzilla.redhat.com/2272563", + "https://bugzilla.redhat.com/show_bug.cgi?id=2272563", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28219", + "https://errata.almalinux.org/8/ALSA-2024-4227.html", + "https://errata.rockylinux.org/RLSA-2024:4227", + "https://github.com/advisories/GHSA-44wm-f244-xhp3", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/2a93aba5cfcf6e241ab4f9392c13e3b74032c061", + "https://linux.oracle.com/cve/CVE-2024-28219.html", + "https://linux.oracle.com/errata/ELSA-2024-4227.html", + "https://lists.debian.org/debian-lts-announce/2024/04/msg00008.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4XLPUT3VK4GQ6EVY525TT2QNUIXNRU5M", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4XLPUT3VK4GQ6EVY525TT2QNUIXNRU5M/", + "https://nvd.nist.gov/vuln/detail/CVE-2024-28219", + "https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.html#security", + "https://ubuntu.com/security/notices/USN-6744-1", + "https://ubuntu.com/security/notices/USN-6744-2", + "https://ubuntu.com/security/notices/USN-6744-3", + "https://www.cve.org/CVERecord?id=CVE-2024-28219" + ], + "PublishedDate": "2024-04-03T03:15:09.71Z", + "LastModifiedDate": "2026-06-17T07:21:12.613Z" + }, + { + "VulnerabilityID": "CVE-2026-54058", + "VendorIDs": [ + "GHSA-62p4-gmf7-7g93" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54058", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:0be22265f4083012c696fc8f4abb95208d60d52892521335cecd261c3aa93f5e", + "Title": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-54058", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d", + "https://github.com/python-pillow/Pillow/pull/9719", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93", + "https://linux.oracle.com/cve/CVE-2026-54058.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54058", + "https://www.cve.org/CVERecord?id=CVE-2026-54058" + ], + "PublishedDate": "2026-07-14T17:17:03.433Z", + "LastModifiedDate": "2026-08-06T15:46:05.867Z" + }, + { + "VulnerabilityID": "CVE-2026-54059", + "VendorIDs": [ + "GHSA-8v84-f9pq-wr9x" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54059", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:73f3d15aa21917ea674cc0ddeb530d8db2a2b333477d42d1a071149bb16d70fd", + "Title": "python-pillow: Pillow: Denial of Service via crafted PCF font data", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54059", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2253.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x", + "https://linux.oracle.com/cve/CVE-2026-54059.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54059", + "https://www.cve.org/CVERecord?id=CVE-2026-54059" + ], + "PublishedDate": "2026-07-06T19:17:08.127Z", + "LastModifiedDate": "2026-07-07T18:58:26.73Z" + }, + { + "VulnerabilityID": "CVE-2026-54060", + "VendorIDs": [ + "GHSA-5x94-69rx-g8h2" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54060", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:78eeca35f30e5314dd8d758f3dafa695e8d5079a9ecbe4803460d082eaf9b981", + "Title": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54060", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2", + "https://linux.oracle.com/cve/CVE-2026-54060.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54060", + "https://www.cve.org/CVERecord?id=CVE-2026-54060" + ], + "PublishedDate": "2026-07-06T19:17:08.27Z", + "LastModifiedDate": "2026-07-07T18:58:45.827Z" + }, + { + "VulnerabilityID": "CVE-2026-55379", + "VendorIDs": [ + "GHSA-45hq-cxwh-f6vc" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55379", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9899e572a0b366211976dc1bd40181800b5bd28ae2d48fe7b7ef81e0a6efdad9", + "Title": "python-pillow: Pillow: Denial of Service via crafted BDF font file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55379", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2255.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc", + "https://linux.oracle.com/cve/CVE-2026-55379.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55379", + "https://www.cve.org/CVERecord?id=CVE-2026-55379" + ], + "PublishedDate": "2026-07-06T19:17:08.577Z", + "LastModifiedDate": "2026-07-07T18:59:01.817Z" + }, + { + "VulnerabilityID": "CVE-2026-55380", + "VendorIDs": [ + "GHSA-phj9-mv4w-65pm" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55380", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:d3e353d60be8c03dd9d2ce9a3c64aaaea4584b60e1e7434f87533f1d77025310", + "Title": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55380", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2256.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm", + "https://linux.oracle.com/cve/CVE-2026-55380.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55380", + "https://www.cve.org/CVERecord?id=CVE-2026-55380" + ], + "PublishedDate": "2026-07-06T19:17:08.703Z", + "LastModifiedDate": "2026-07-07T18:58:54.647Z" + }, + { + "VulnerabilityID": "CVE-2026-59197", + "VendorIDs": [ + "GHSA-xj96-63gp-2gmr" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59197", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:90e4cd0a04c357606046a24a491416e42daeddcf77184d73c9b717ecdddb02ed", + "Title": "Pillow: Pillow: Native heap out-of-bounds write", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-59197", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1", + "https://github.com/python-pillow/Pillow/pull/9695", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr", + "https://linux.oracle.com/cve/CVE-2026-59197.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59197", + "https://www.cve.org/CVERecord?id=CVE-2026-59197" + ], + "PublishedDate": "2026-07-14T17:17:14.487Z", + "LastModifiedDate": "2026-07-21T19:17:11.907Z" + }, + { + "VulnerabilityID": "CVE-2026-59199", + "VendorIDs": [ + "GHSA-6r8x-57c9-28j4" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59199", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:776c73133a99f59a34394c7841f0a6e55859e44f8889310565bf7236b80df10a", + "Title": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59199", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3451.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b", + "https://github.com/python-pillow/Pillow/pull/9703", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59199", + "https://www.cve.org/CVERecord?id=CVE-2026-59199" + ], + "PublishedDate": "2026-07-14T16:17:01.937Z", + "LastModifiedDate": "2026-07-15T16:16:49.487Z" + }, + { + "VulnerabilityID": "CVE-2026-59200", + "VendorIDs": [ + "GHSA-jjj6-mw9f-p565" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59200", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:cfff3b87d5561da6bc562696d7b4c227186f7d840f2cd199e06e36994d5b8602", + "Title": "Pillow: Pillow: Denial of service via crafted PDF stream", + "Description": "Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59200", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09", + "https://github.com/python-pillow/Pillow/pull/9718", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59200", + "https://www.cve.org/CVERecord?id=CVE-2026-59200" + ], + "PublishedDate": "2026-07-14T17:17:14.62Z", + "LastModifiedDate": "2026-07-21T15:52:40.107Z" + }, + { + "VulnerabilityID": "CVE-2026-59204", + "VendorIDs": [ + "GHSA-vjc4-5qp5-m44j" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59204", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:6619288a1b2dd5a8ef3e220b12f42db6ac601305c87529663922d764e1ee8b42", + "Title": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image", + "Description": "Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59204", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca", + "https://github.com/python-pillow/Pillow/pull/9704", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59204", + "https://www.cve.org/CVERecord?id=CVE-2026-59204" + ], + "PublishedDate": "2026-07-14T16:17:02.227Z", + "LastModifiedDate": "2026-07-21T19:17:12.02Z" + }, + { + "VulnerabilityID": "CVE-2026-59205", + "VendorIDs": [ + "GHSA-9hw9-ch79-4vh6" + ], + "PkgName": "Pillow", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/Pillow-8.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@8.2.0", + "UID": "9825e9671e357e7f" + }, + "InstalledVersion": "8.2.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59205", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3a67001a9558792afd73d8a4f18738d7399c0f565e737b052818950de21fa425", + "Title": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59205", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3453.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721", + "https://github.com/python-pillow/Pillow/pull/9715", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59205", + "https://www.cve.org/CVERecord?id=CVE-2026-59205" + ], + "PublishedDate": "2026-07-14T16:17:02.37Z", + "LastModifiedDate": "2026-07-14T20:09:27.77Z" + }, + { + "VulnerabilityID": "CVE-2023-37920", + "VendorIDs": [ + "GHSA-xqr8-7jwr-rhp7" + ], + "PkgName": "certifi", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/certifi-2022.9.24-py3.10.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/certifi@2022.9.24", + "UID": "99eb2e43c4ab4220" + }, + "InstalledVersion": "2022.9.24", + "FixedVersion": "2023.7.22", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-37920", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:28db73a82c68a40f931b0a580e33f2f6cf57e5236b44223fec55b465e8c96c04", + "Title": "python-certifi: Removal of e-Tugra root certificate", + "Description": "Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes \"e-Tugra\" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from \"e-Tugra\" from the root store.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-345" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "ghsa": 3, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 1 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:7753", + "https://access.redhat.com/security/cve/CVE-2023-37920", + "https://bugzilla.redhat.com/2226586", + "https://bugzilla.redhat.com/2242493", + "https://errata.almalinux.org/9/ALSA-2023-7753.html", + "https://github.com/certifi/python-certifi", + "https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909", + "https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7", + "https://github.com/pypa/advisory-database/tree/main/vulns/certifi/PYSEC-2023-135.yaml", + "https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A", + "https://linux.oracle.com/cve/CVE-2023-37920.html", + "https://linux.oracle.com/errata/ELSA-2024-0133.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-37920", + "https://security.netapp.com/advisory/ntap-20240912-0002", + "https://security.netapp.com/advisory/ntap-20240912-0002/", + "https://www.cve.org/CVERecord?id=CVE-2023-37920" + ], + "PublishedDate": "2023-07-25T21:15:10.827Z", + "LastModifiedDate": "2026-06-17T06:08:54.337Z" + }, + { + "VulnerabilityID": "CVE-2023-0286", + "VendorIDs": [ + "GHSA-x4qr-2fvf-3mr5" + ], + "PkgName": "cryptography", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/cryptography-38.0.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/cryptography@38.0.3", + "UID": "9693148644a00cfd" + }, + "InstalledVersion": "38.0.3", + "FixedVersion": "39.0.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-0286", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:789fbd54d1472797e0697f631b60c5d46eec6e349b9e0e341f5f53c86c107443", + "Title": "openssl: X.400 address type confusion in X.509 GeneralName", + "Description": "There is a type confusion vulnerability relating to X.400 address processing\ninside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but\nthe public structure definition for GENERAL_NAME incorrectly specified the type\nof the x400Address field as ASN1_TYPE. This field is subsequently interpreted by\nthe OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an\nASN1_STRING.\n\nWhen CRL checking is enabled (i.e. the application sets the\nX509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass\narbitrary pointers to a memcmp call, enabling them to read memory contents or\nenact a denial of service. In most cases, the attack requires the attacker to\nprovide both the certificate chain and CRL, neither of which need to have a\nvalid signature. If the attacker only controls one of these inputs, the other\ninput must already contain an X.400 address as a CRL distribution point, which\nis uncommon. As such, this vulnerability is most likely to only affect\napplications which have implemented their own functionality for retrieving CRLs\nover a network.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-843" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "julia": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 7.4 + }, + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 7.4 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 7.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0946", + "https://access.redhat.com/errata/RHSA-2025:7937", + "https://access.redhat.com/security/cve/CVE-2023-0286", + "https://access.redhat.com/security/cve/cve-2023-0286", + "https://bugzilla.redhat.com/2164440", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144000", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144003", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144006", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144008", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144010", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144012", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144015", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144017", + "https://bugzilla.redhat.com/show_bug.cgi?id=2144019", + "https://bugzilla.redhat.com/show_bug.cgi?id=2145170", + "https://bugzilla.redhat.com/show_bug.cgi?id=2158412", + "https://bugzilla.redhat.com/show_bug.cgi?id=2164440", + "https://bugzilla.redhat.com/show_bug.cgi?id=2164487", + "https://bugzilla.redhat.com/show_bug.cgi?id=2164488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2164492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2164494", + "https://bugzilla.redhat.com/show_bug.cgi?id=2164497", + "https://bugzilla.redhat.com/show_bug.cgi?id=2164499", + "https://bugzilla.redhat.com/show_bug.cgi?id=2164500", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4203", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4304", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4450", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0215", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0216", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0217", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0286", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0401", + "https://errata.almalinux.org/9/ALSA-2025-7937.html", + "https://errata.rockylinux.org/RLSA-2023:0946", + "https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.2-relnotes.txt", + "https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x509.patch.sig", + "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9", + "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2f7530077e0ef79d98718138716bc51ca0cad658", + "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fd2af07dc083a350c959147097003a14a5e8ac4d", + "https://github.com/advisories/GHSA-x4qr-2fvf-3mr5", + "https://github.com/pyca/cryptography", + "https://github.com/pyca/cryptography/security/advisories/GHSA-x4qr-2fvf-3mr5", + "https://linux.oracle.com/cve/CVE-2023-0286.html", + "https://linux.oracle.com/errata/ELSA-2025-7937.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-0286", + "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003", + "https://rustsec.org/advisories/RUSTSEC-2023-0006.html", + "https://security.gentoo.org/glsa/202402-08", + "https://ubuntu.com/security/notices/USN-5844-1", + "https://ubuntu.com/security/notices/USN-5845-1", + "https://ubuntu.com/security/notices/USN-5845-2", + "https://ubuntu.com/security/notices/USN-6564-1", + "https://ubuntu.com/security/notices/USN-7894-1", + "https://www.cve.org/CVERecord?id=CVE-2023-0286", + "https://www.openssl.org/news/secadv/20230207.txt" + ], + "PublishedDate": "2023-02-08T20:15:24.267Z", + "LastModifiedDate": "2026-06-17T05:25:12.637Z" + }, + { + "VulnerabilityID": "CVE-2023-50782", + "VendorIDs": [ + "GHSA-3ww4-gg4f-jr7f" + ], + "PkgName": "cryptography", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/cryptography-38.0.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/cryptography@38.0.3", + "UID": "9693148644a00cfd" + }, + "InstalledVersion": "38.0.3", + "FixedVersion": "42.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-50782", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:d90d1b3b20a9ef653ffef2319504c65c0e4d8520b05dca8a59a50df2012e1318", + "Title": "python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659", + "Description": "A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-203" + ], + "VendorSeverity": { + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2023-50782", + "https://bugzilla.redhat.com/show_bug.cgi?id=2254432", + "https://github.com/openssl/openssl/pull/13817", + "https://github.com/pyca/cryptography", + "https://github.com/pyca/cryptography/issues/9785", + "https://nvd.nist.gov/vuln/detail/CVE-2023-50782", + "https://people.redhat.com/~hkario/marvin/", + "https://ubuntu.com/security/notices/USN-6663-1", + "https://ubuntu.com/security/notices/USN-6673-1", + "https://ubuntu.com/security/notices/USN-6673-2", + "https://www.couchbase.com/alerts", + "https://www.couchbase.com/alerts/", + "https://www.cve.org/CVERecord?id=CVE-2023-50782" + ], + "PublishedDate": "2024-02-05T21:15:11.183Z", + "LastModifiedDate": "2026-06-17T06:39:58.24Z" + }, + { + "VulnerabilityID": "CVE-2024-26130", + "VendorIDs": [ + "GHSA-6vqw-3v5j-54x4" + ], + "PkgName": "cryptography", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/cryptography-38.0.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/cryptography@38.0.3", + "UID": "9693148644a00cfd" + }, + "InstalledVersion": "38.0.3", + "FixedVersion": "42.0.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-26130", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:795b9b3de65853ab2c4482a31621a73de4b1f9af6e855239d60059fb44905aec", + "Title": "python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override", + "Description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "alma": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:15608", + "https://access.redhat.com/security/cve/CVE-2024-26130", + "https://bugzilla.redhat.com/2269617", + "https://bugzilla.redhat.com/show_bug.cgi?id=2269617", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26130", + "https://errata.almalinux.org/9/ALSA-2025-15608.html", + "https://errata.rockylinux.org/RLSA-2025:15608", + "https://github.com/pyca/cryptography", + "https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55", + "https://github.com/pyca/cryptography/pull/10423", + "https://github.com/pyca/cryptography/security/advisories/GHSA-6vqw-3v5j-54x4", + "https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2024-225.yaml", + "https://linux.oracle.com/cve/CVE-2024-26130.html", + "https://linux.oracle.com/errata/ELSA-2025-20364.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-26130", + "https://ubuntu.com/security/notices/USN-6673-1", + "https://ubuntu.com/security/notices/USN-6673-3", + "https://www.cve.org/CVERecord?id=CVE-2024-26130" + ], + "PublishedDate": "2024-02-21T17:15:09.863Z", + "LastModifiedDate": "2026-06-17T07:17:09.793Z" + }, + { + "VulnerabilityID": "CVE-2026-26007", + "VendorIDs": [ + "GHSA-r6ph-v2qm-q3c2" + ], + "PkgName": "cryptography", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/cryptography-38.0.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/cryptography@38.0.3", + "UID": "9693148644a00cfd" + }, + "InstalledVersion": "38.0.3", + "FixedVersion": "46.0.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-26007", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:5c353f20bd310f7f7a61744c14ed7c64b306ac3c2cb99ae8f113646c377e563d", + "Title": "cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves", + "Description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-345", + "CWE-354" + ], + "VendorSeverity": { + "alma": 3, + "azure": 3, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V40Score": 8.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/02/10/4", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:12176", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13553", + "https://access.redhat.com/errata/RHSA-2026:13672", + "https://access.redhat.com/errata/RHSA-2026:19355", + "https://access.redhat.com/errata/RHSA-2026:21431", + "https://access.redhat.com/errata/RHSA-2026:21517", + "https://access.redhat.com/errata/RHSA-2026:22330", + "https://access.redhat.com/errata/RHSA-2026:22993", + "https://access.redhat.com/errata/RHSA-2026:2694", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:6308", + "https://access.redhat.com/errata/RHSA-2026:6309", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:7295", + "https://access.redhat.com/security/cve/CVE-2026-26007", + "https://bugzilla.redhat.com/2438762", + "https://bugzilla.redhat.com/2447194", + "https://bugzilla.redhat.com/2448553", + "https://bugzilla.redhat.com/show_bug.cgi?id=2438762", + "https://bugzilla.redhat.com/show_bug.cgi?id=2447194", + "https://bugzilla.redhat.com/show_bug.cgi?id=2448553", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26007", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-30922", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32597", + "https://errata.almalinux.org/8/ALSA-2026-12176.html", + "https://errata.rockylinux.org/RLSA-2026:19355", + "https://github.com/pyca/cryptography", + "https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c", + "https://github.com/pyca/cryptography/releases/tag/46.0.5", + "https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2", + "https://linux.oracle.com/cve/CVE-2026-26007.html", + "https://linux.oracle.com/errata/ELSA-2026-19355.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-26007", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26007.json", + "https://ubuntu.com/security/notices/USN-8087-1", + "https://ubuntu.com/security/notices/USN-8087-3", + "https://www.cve.org/CVERecord?id=CVE-2026-26007" + ], + "PublishedDate": "2026-02-10T22:17:00.307Z", + "LastModifiedDate": "2026-08-12T12:18:11.08Z" + }, + { + "VulnerabilityID": "CVE-2026-69249", + "VendorIDs": [ + "GHSA-jwv3-5hgf-82ww" + ], + "PkgName": "cryptography", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/cryptography-38.0.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/cryptography@38.0.3", + "UID": "9693148644a00cfd" + }, + "InstalledVersion": "38.0.3", + "FixedVersion": "49.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-69249", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9cd4cf9d7b48c52a34b6003bbf18bbc93b43e60f2e573adb35647fdf0232da9d", + "Title": "python-cryptography is a package designed to expose cryptographic prim ...", + "Description": "python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + } + }, + "References": [ + "https://github.com/pyca/cryptography", + "https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582", + "https://github.com/pyca/cryptography/pull/14960", + "https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww" + ], + "PublishedDate": "2026-08-03T22:16:52.72Z", + "LastModifiedDate": "2026-08-04T15:16:43.86Z" + }, + { + "VulnerabilityID": "GHSA-537c-gmf6-5ccf", + "PkgName": "cryptography", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/cryptography-38.0.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/cryptography@38.0.3", + "UID": "9693148644a00cfd" + }, + "InstalledVersion": "38.0.3", + "FixedVersion": "48.0.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-537c-gmf6-5ccf", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:8cbc3d1c2f14628aaee53dc799b7e13925070e3f1cdcd01523733575ae0013f4", + "Title": "Vulnerable OpenSSL included in cryptography wheels", + "Description": "pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/pyca/cryptography", + "https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf", + "https://openssl-library.org/news/secadv/20260609.txt" + ], + "PublishedDate": "2026-06-15T20:12:27Z", + "LastModifiedDate": "2026-06-15T20:12:27Z" + }, + { + "VulnerabilityID": "CVE-2023-45139", + "VendorIDs": [ + "GHSA-6673-4983-2vx5" + ], + "PkgName": "fonttools", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/fonttools-4.38.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/fonttools@4.38.0", + "UID": "4c09aa3618b844c9" + }, + "InstalledVersion": "4.38.0", + "FixedVersion": "4.43.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45139", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:246ad5d54525939ac024125cd0f6df51c16ddb8891a44638ef7d4d2bff396cc4", + "Title": "fonttools: XML External Entity Injection (XXE) Vulnerability", + "Description": "fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-611" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2024/03/08/2", + "http://www.openwall.com/lists/oss-security/2024/03/09/1", + "https://access.redhat.com/security/cve/CVE-2023-45139", + "https://github.com/fonttools/fonttools", + "https://github.com/fonttools/fonttools/commit/9f61271dc1ca82ed91f529b130fe5dc5c9bf1f4c", + "https://github.com/fonttools/fonttools/releases/tag/4.43.0", + "https://github.com/fonttools/fonttools/security/advisories/GHSA-6673-4983-2vx5", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VY63B4SGY4QOQGUXMECRGD6K3YT3GJ75", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VY63B4SGY4QOQGUXMECRGD6K3YT3GJ75/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45139", + "https://ubuntu.com/security/notices/USN-7917-1", + "https://www.cve.org/CVERecord?id=CVE-2023-45139" + ], + "PublishedDate": "2024-01-10T16:15:46.767Z", + "LastModifiedDate": "2026-06-17T06:28:17.89Z" + }, + { + "VulnerabilityID": "CVE-2022-40899", + "VendorIDs": [ + "GHSA-v3c5-jqr6-7qm8" + ], + "PkgName": "future", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/future-0.18.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/future@0.18.2", + "UID": "8509fe8feed9632b" + }, + "InstalledVersion": "0.18.2", + "FixedVersion": "0.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-40899", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a882654991590f48c33a0e1a9dffdc9718d4ec9d0740c6928107cc9522dfe543", + "Title": "python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server", + "Description": "An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "amazon": 2, + "ghsa": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-40899", + "https://github.com/PythonCharmers/python-future", + "https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215", + "https://github.com/PythonCharmers/python-future/commit/c91d70b34ef0402aef3e9d04364ba98509dca76f", + "https://github.com/PythonCharmers/python-future/pull/610", + "https://github.com/pypa/advisory-database/tree/main/vulns/future/PYSEC-2022-42991.yaml", + "https://github.com/python/cpython/pull/17157", + "https://nvd.nist.gov/vuln/detail/CVE-2022-40899", + "https://pypi.org/project/future", + "https://pypi.org/project/future/", + "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages", + "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/", + "https://ubuntu.com/security/notices/USN-5833-1", + "https://www.cve.org/CVERecord?id=CVE-2022-40899" + ], + "PublishedDate": "2022-12-23T00:15:14.11Z", + "LastModifiedDate": "2026-06-17T05:02:13.347Z" + }, + { + "VulnerabilityID": "GHSA-6v7p-g79w-8964", + "PkgName": "msgpack", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/msgpack-1.0.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/msgpack@1.0.4", + "UID": "452ea5dc8d115044" + }, + "InstalledVersion": "1.0.4", + "FixedVersion": "1.2.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-6v7p-g79w-8964", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c45c579a4353c2016dbbafdfb6bc663ba2fe30e94989a776a64ae6d3883cef41", + "Title": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error", + "Description": "### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.\n\nTherefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/msgpack/msgpack-python", + "https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d", + "https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1", + "https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964" + ], + "PublishedDate": "2026-06-19T21:42:55Z", + "LastModifiedDate": "2026-06-19T21:42:55Z" + }, + { + "VulnerabilityID": "CVE-2026-27459", + "VendorIDs": [ + "GHSA-5pwr-322w-8jr4" + ], + "PkgName": "pyOpenSSL", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/pyOpenSSL-22.1.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pyopenssl@22.1.0", + "UID": "c9eaaa96ffe415fd" + }, + "InstalledVersion": "22.1.0", + "FixedVersion": "26.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27459", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a57e24f2533448049c4277cb724346a1b45589264f94aa4b29e04e31b67c857a", + "Title": "pyOpenSSL: DTLS cookie callback buffer overflow", + "Description": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-120" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "nvd": 4, + "photon": 4, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U", + "V40Score": 7.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10754", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13553", + "https://access.redhat.com/errata/RHSA-2026:14835", + "https://access.redhat.com/errata/RHSA-2026:14873", + "https://access.redhat.com/errata/RHSA-2026:14874", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:48085", + "https://access.redhat.com/errata/RHSA-2026:7224", + "https://access.redhat.com/errata/RHSA-2026:8437", + "https://access.redhat.com/security/cve/CVE-2026-27459", + "https://bugzilla.redhat.com/show_bug.cgi?id=2448503", + "https://github.com/pyca/pyopenssl", + "https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst", + "https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408", + "https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27459", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json", + "https://ubuntu.com/security/notices/USN-8115-1", + "https://www.cve.org/CVERecord?id=CVE-2026-27459" + ], + "PublishedDate": "2026-03-18T00:16:19.273Z", + "LastModifiedDate": "2026-08-12T12:18:17.263Z" + }, + { + "VulnerabilityID": "CVE-2022-40897", + "VendorIDs": [ + "GHSA-r9hx-vwmv-q579" + ], + "PkgName": "setuptools", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/setuptools-65.5.0-py3.10.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@65.5.0", + "UID": "76bc4d464905d99d" + }, + "InstalledVersion": "65.5.0", + "FixedVersion": "65.5.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-40897", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b5c243ffb1e8b491ce8256032895f0d5502f128ed48104bc2a58ebbe94c77dbb", + "Title": "pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py", + "Description": "Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1333" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "bitnami": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "photon": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:L/SI:L/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0952", + "https://access.redhat.com/security/cve/CVE-2022-40897", + "https://bugzilla.redhat.com/2158559", + "https://bugzilla.redhat.com/show_bug.cgi?id=2158559", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40897", + "https://errata.almalinux.org/9/ALSA-2023-0952.html", + "https://errata.rockylinux.org/RLSA-2023:0952", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2022-43012.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/fe8a98e696241487ba6ac9f91faa38ade939ec5d/setuptools/package_index.py#L200", + "https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be", + "https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1", + "https://github.com/pypa/setuptools/issues/3659", + "https://linux.oracle.com/cve/CVE-2022-40897.html", + "https://linux.oracle.com/errata/ELSA-2024-2987.html", + "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-40897", + "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages", + "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/", + "https://pyup.io/vulnerabilities/CVE-2022-40897/52495", + "https://pyup.io/vulnerabilities/CVE-2022-40897/52495/", + "https://security.netapp.com/advisory/ntap-20230214-0001", + "https://security.netapp.com/advisory/ntap-20230214-0001/", + "https://security.netapp.com/advisory/ntap-20240621-0006", + "https://security.netapp.com/advisory/ntap-20240621-0006/", + "https://setuptools.pypa.io/en/latest", + "https://ubuntu.com/security/notices/USN-5817-1", + "https://www.cve.org/CVERecord?id=CVE-2022-40897" + ], + "PublishedDate": "2022-12-23T00:15:13.987Z", + "LastModifiedDate": "2026-06-17T05:02:12.993Z" + }, + { + "VulnerabilityID": "CVE-2024-6345", + "VendorIDs": [ + "GHSA-cx63-2mw6-8hw5" + ], + "PkgName": "setuptools", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/setuptools-65.5.0-py3.10.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@65.5.0", + "UID": "76bc4d464905d99d" + }, + "InstalledVersion": "65.5.0", + "FixedVersion": "70.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-6345", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:4a285e365a2970ad032b9c2bf2b61c70eb8b96f5bd4d0043416480d4b2971920", + "Title": "pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools", + "Description": "A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "ghsa": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 8.8, + "V40Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:6726", + "https://access.redhat.com/security/cve/CVE-2024-6345", + "https://bugzilla.redhat.com/2297771", + "https://bugzilla.redhat.com/show_bug.cgi?id=2297771", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6345", + "https://errata.almalinux.org/9/ALSA-2024-6726.html", + "https://errata.rockylinux.org/RLSA-2024:6726", + "https://github.com/advisories/GHSA-cx63-2mw6-8hw5", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0", + "https://github.com/pypa/setuptools/pull/4332", + "https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5", + "https://linux.oracle.com/cve/CVE-2024-6345.html", + "https://linux.oracle.com/errata/ELSA-2024-6726.html", + "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-6345", + "https://ubuntu.com/security/notices/USN-7002-1", + "https://www.cve.org/CVERecord?id=CVE-2024-6345" + ], + "PublishedDate": "2024-07-15T01:15:01.73Z", + "LastModifiedDate": "2026-06-17T08:17:49.463Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgName": "setuptools", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/setuptools-65.5.0-py3.10.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@65.5.0", + "UID": "76bc4d464905d99d" + }, + "InstalledVersion": "65.5.0", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:ee455b659a4027525abc07d58a9b3eea5688723602744429335b8430fe97cd69", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:13578", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/9/ALSA-2025-13578.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + }, + { + "VulnerabilityID": "CVE-2024-52804", + "VendorIDs": [ + "GHSA-8w49-h785-mj3c" + ], + "PkgName": "tornado", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/tornado-6.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.1", + "UID": "6782ac4b2289adcb" + }, + "InstalledVersion": "6.1", + "FixedVersion": "6.4.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-52804", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:4759bfcb0955e5bcb209797ce3de1c85c7da9cf4e59a726ab08d05ce44df1024", + "Title": "python-tornado: Tornado has HTTP cookie parsing DoS vulnerability", + "Description": "Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "ghsa": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:10590", + "https://access.redhat.com/security/cve/CVE-2024-52804", + "https://bugzilla.redhat.com/2328045", + "https://bugzilla.redhat.com/show_bug.cgi?id=2328045", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52804", + "https://errata.almalinux.org/9/ALSA-2024-10590.html", + "https://errata.rockylinux.org/RLSA-2024:10590", + "https://github.com/advisories/GHSA-7pwv-g7hj-39pr", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/d5ba4a1695fbf7c6a3e54313262639b198291533", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-8w49-h785-mj3c", + "https://linux.oracle.com/cve/CVE-2024-52804.html", + "https://linux.oracle.com/errata/ELSA-2025-2872.html", + "https://lists.debian.org/debian-lts-announce/2025/01/msg00000.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-52804", + "https://ubuntu.com/security/notices/USN-7150-1", + "https://www.cve.org/CVERecord?id=CVE-2024-52804" + ], + "PublishedDate": "2024-11-22T16:15:34.417Z", + "LastModifiedDate": "2026-06-17T08:07:39.533Z" + }, + { + "VulnerabilityID": "CVE-2025-47287", + "VendorIDs": [ + "GHSA-7cx3-6m66-7c5m" + ], + "PkgName": "tornado", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/tornado-6.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.1", + "UID": "6782ac4b2289adcb" + }, + "InstalledVersion": "6.1", + "FixedVersion": "6.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47287", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a1b4f2e1e54ccb86dde674b11df68a6ad7e7fc0effed0bfe722c4e2dc18a3b45", + "Title": "tornado: Tornado Multipart Form-Data Denial of Service", + "Description": "Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "ghsa": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:8136", + "https://access.redhat.com/security/cve/CVE-2025-47287", + "https://bugzilla.redhat.com/2366703", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366703", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47287", + "https://errata.almalinux.org/9/ALSA-2025-8136.html", + "https://errata.rockylinux.org/RLSA-2025:8136", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/b39b892bf78fe8fea01dd45199aa88307e7162f3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5m", + "https://linux.oracle.com/cve/CVE-2025-47287.html", + "https://linux.oracle.com/errata/ELSA-2025-8664.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00038.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47287", + "https://ubuntu.com/security/notices/USN-7547-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47287" + ], + "PublishedDate": "2025-05-15T22:15:18.827Z", + "LastModifiedDate": "2026-06-17T09:27:40.32Z" + }, + { + "VulnerabilityID": "CVE-2025-67725", + "VendorIDs": [ + "GHSA-c98p-7wgm-6p64" + ], + "PkgName": "tornado", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/tornado-6.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.1", + "UID": "6782ac4b2289adcb" + }, + "InstalledVersion": "6.1", + "FixedVersion": "6.5.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-67725", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:68ffa51679f40131800d7f32d32634e1c3d68a790a6b9ec6228021123b5b296d", + "Title": "tornado: Tornado Quadratic DoS via Repeated Header Coalescing", + "Description": "Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS). Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if max_header_size has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0930", + "https://access.redhat.com/security/cve/CVE-2025-67725", + "https://bugzilla.redhat.com/2421722", + "https://bugzilla.redhat.com/2421733", + "https://errata.almalinux.org/8/ALSA-2026-0930.html", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-266.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c98p-7wgm-6p64", + "https://linux.oracle.com/cve/CVE-2025-67725.html", + "https://linux.oracle.com/errata/ELSA-2026-0930.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-67725", + "https://ubuntu.com/security/notices/USN-7950-1", + "https://www.cve.org/CVERecord?id=CVE-2025-67725" + ], + "PublishedDate": "2025-12-12T06:15:41.38Z", + "LastModifiedDate": "2026-06-17T09:58:02.337Z" + }, + { + "VulnerabilityID": "CVE-2025-67726", + "VendorIDs": [ + "GHSA-jhmp-mqwm-3gq8" + ], + "PkgName": "tornado", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/tornado-6.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.1", + "UID": "6782ac4b2289adcb" + }, + "InstalledVersion": "6.1", + "FixedVersion": "6.5.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-67726", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:aee00ea71eb043872c4d7875fdfbd810428b8ead0940665f629390737edad27a", + "Title": "tornado: Tornado Quadratic DoS via Crafted Multipart Parameters", + "Description": "Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.py is used to parse specific HTTP header values, such as those in multipart/form-data and repeatedly calls string.count() within a nested loop while processing quoted semicolons. If an attacker sends a request with a large number of maliciously crafted parameters in a Content-Disposition header, the server's CPU usage increases quadratically (O(n²)) during parsing. Due to Tornado's single event loop architecture, a single malicious request can cause the entire server to become unresponsive for an extended period. This issue is fixed in version 6.5.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-834" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0930", + "https://access.redhat.com/security/cve/CVE-2025-67726", + "https://bugzilla.redhat.com/2421722", + "https://bugzilla.redhat.com/2421733", + "https://errata.almalinux.org/8/ALSA-2026-0930.html", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-267.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-jhmp-mqwm-3gq8", + "https://linux.oracle.com/cve/CVE-2025-67726.html", + "https://linux.oracle.com/errata/ELSA-2026-0930.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-67726", + "https://ubuntu.com/security/notices/USN-7950-1", + "https://www.cve.org/CVERecord?id=CVE-2025-67726" + ], + "PublishedDate": "2025-12-12T07:15:44.92Z", + "LastModifiedDate": "2026-06-17T09:58:02.44Z" + }, + { + "VulnerabilityID": "CVE-2026-31958", + "VendorIDs": [ + "GHSA-qjxf-f2mg-c6mc" + ], + "PkgName": "tornado", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/tornado-6.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.1", + "UID": "6782ac4b2289adcb" + }, + "InstalledVersion": "6.1", + "FixedVersion": "6.5.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-31958", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:ad9587c24477072c9fd7ad485d6fce9cc1ce0d83f94b57b247b861b247e4b897", + "Title": "tornado-python: Tornado: Denial of Service via large multipart bodies", + "Description": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:19189", + "https://access.redhat.com/security/cve/CVE-2026-31958", + "https://bugzilla.redhat.com/2446765", + "https://bugzilla.redhat.com/2454716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", + "https://bugzilla.redhat.com/show_bug.cgi?id=2454716", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31958", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35536", + "https://errata.almalinux.org/9/ALSA-2026-19189.html", + "https://errata.rockylinux.org/RLSA-2026:19189", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2026-140.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc", + "https://linux.oracle.com/cve/CVE-2026-31958.html", + "https://linux.oracle.com/errata/ELSA-2026-8093.html", + "https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-31958", + "https://ubuntu.com/security/notices/USN-8198-1", + "https://ubuntu.com/security/notices/USN-8198-2", + "https://www.cve.org/CVERecord?id=CVE-2026-31958" + ], + "PublishedDate": "2026-03-11T20:16:16.617Z", + "LastModifiedDate": "2026-06-17T10:34:50.473Z" + }, + { + "VulnerabilityID": "CVE-2026-35536", + "VendorIDs": [ + "GHSA-fqwm-6jpj-5wxc" + ], + "PkgName": "tornado", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/tornado-6.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.1", + "UID": "6782ac4b2289adcb" + }, + "InstalledVersion": "6.1", + "FixedVersion": "6.5.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-35536", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9ae8a07f06ef5c9042805cdf15a85e8c692a89428be0ad9caab8ba0d6de31882", + "Title": "tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments", + "Description": "In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-159" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "photon": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N", + "V3Score": 7.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", + "V3Score": 5.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:19189", + "https://access.redhat.com/security/cve/CVE-2026-35536", + "https://bugzilla.redhat.com/2446765", + "https://bugzilla.redhat.com/2454716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", + "https://bugzilla.redhat.com/show_bug.cgi?id=2454716", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31958", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35536", + "https://errata.almalinux.org/9/ALSA-2026-19189.html", + "https://errata.rockylinux.org/RLSA-2026:19189", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7", + "https://linux.oracle.com/cve/CVE-2026-35536.html", + "https://linux.oracle.com/errata/ELSA-2026-24342.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-35536", + "https://ubuntu.com/security/notices/USN-8198-1", + "https://ubuntu.com/security/notices/USN-8198-2", + "https://www.cve.org/CVERecord?id=CVE-2026-35536" + ], + "PublishedDate": "2026-04-03T04:16:53.55Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-49853", + "VendorIDs": [ + "GHSA-3x9g-8vmp-wqvf" + ], + "PkgName": "tornado", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/tornado-6.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.1", + "UID": "6782ac4b2289adcb" + }, + "InstalledVersion": "6.1", + "FixedVersion": "6.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49853", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:408e3513275d75ca820d75c312531954d0b89c9792a700a7dc2fc77b68ffb4d4", + "Title": "Tornado is a Python web framework and asynchronous networking library. ...", + "Description": "Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "photon": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 7.7 + } + }, + "References": [ + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/aba2569f7ed7a6bdbef816658fb6b7182531b751", + "https://github.com/tornadoweb/tornado/pull/3626", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.6", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf" + ], + "PublishedDate": "2026-07-14T21:17:02.13Z", + "LastModifiedDate": "2026-07-21T16:17:13.477Z" + }, + { + "VulnerabilityID": "CVE-2026-49855", + "VendorIDs": [ + "GHSA-mgf9-4vpg-hj56" + ], + "PkgName": "tornado", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/tornado-6.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.1", + "UID": "6782ac4b2289adcb" + }, + "InstalledVersion": "6.1", + "FixedVersion": "6.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49855", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:5ffda345eda101c8166492c4ccacf1aa69451b8bb41feeffdff501e3c5b3f7ff", + "Title": "Tornado is a Python web framework and asynchronous networking library. ...", + "Description": "Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "photon": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff", + "https://github.com/tornadoweb/tornado/pull/3626", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56" + ], + "PublishedDate": "2026-07-14T21:17:02.437Z", + "LastModifiedDate": "2026-07-16T16:19:10.69Z" + }, + { + "VulnerabilityID": "CVE-2023-43804", + "VendorIDs": [ + "GHSA-v845-jxx5-vc9f" + ], + "PkgName": "urllib3", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/urllib3-1.26.11.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@1.26.11", + "UID": "bdec38cefac9e3a1" + }, + "InstalledVersion": "1.26.11", + "FixedVersion": "2.0.6, 1.26.17", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-43804", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:2614f408450249b8d3704fe14c02e7c1c24da71f9c5f432a8340e53718b04245", + "Title": "python-urllib3: Cookie request header isn't stripped during cross-origin redirects", + "Description": "urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "azure": 3, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", + "V3Score": 5.9, + "V40Score": 7.4 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:2159", + "https://access.redhat.com/errata/RHSA-2024:2987", + "https://access.redhat.com/security/cve/CVE-2023-43804", + "https://bugzilla.redhat.com/2242493", + "https://bugzilla.redhat.com/show_bug.cgi?id=2158559", + "https://bugzilla.redhat.com/show_bug.cgi?id=2240059", + "https://bugzilla.redhat.com/show_bug.cgi?id=2242493", + "https://bugzilla.redhat.com/show_bug.cgi?id=2249755", + "https://bugzilla.redhat.com/show_bug.cgi?id=2257854", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40897", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48560", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48565", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-43804", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22195", + "https://errata.almalinux.org/9/ALSA-2024-2159.html", + "https://errata.rockylinux.org/RLSA-2024:2987", + "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-192.yaml", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aafb", + "https://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a2056d", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9f", + "https://linux.oracle.com/cve/CVE-2023-43804.html", + "https://linux.oracle.com/errata/ELSA-2024-2987.html", + "https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html", + "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3PR7C6RJ6JUBQKIJ644DMIJSUP36VDY", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3PR7C6RJ6JUBQKIJ644DMIJSUP36VDY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAGZXYJ7H2G3SB47M453VQVNAWKAEJJ", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAGZXYJ7H2G3SB47M453VQVNAWKAEJJ/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-43804", + "https://security.netapp.com/advisory/ntap-20241213-0007", + "https://security.netapp.com/advisory/ntap-20241213-0007/", + "https://ubuntu.com/security/notices/USN-6473-1", + "https://ubuntu.com/security/notices/USN-6473-2", + "https://www.cve.org/CVERecord?id=CVE-2023-43804", + "https://www.vicarius.io/vsociety/posts/cve-2023-43804-urllib3-vulnerability-3" + ], + "PublishedDate": "2023-10-04T17:15:10.163Z", + "LastModifiedDate": "2026-06-17T06:26:29.04Z" + }, + { + "VulnerabilityID": "CVE-2025-66418", + "VendorIDs": [ + "GHSA-gm62-xv2j-4w53" + ], + "PkgName": "urllib3", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/urllib3-1.26.11.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@1.26.11", + "UID": "bdec38cefac9e3a1" + }, + "InstalledVersion": "1.26.11", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66418", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:d5b64cb5a5a25066fd5477d1393eb798c2b2782722960bf1cc4d3cbf85b2ad93", + "Title": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66418", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53", + "https://linux.oracle.com/cve/CVE-2025-66418.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66418", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://www.cve.org/CVERecord?id=CVE-2025-66418", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T16:15:51.053Z", + "LastModifiedDate": "2026-06-17T09:56:48.383Z" + }, + { + "VulnerabilityID": "CVE-2025-66471", + "VendorIDs": [ + "GHSA-2xpw-w6gg-jr37" + ], + "PkgName": "urllib3", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/urllib3-1.26.11.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@1.26.11", + "UID": "bdec38cefac9e3a1" + }, + "InstalledVersion": "1.26.11", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66471", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:d27b04c39233d3166221388475787c1b0707c47fce0553e8855efb04e77a74ac", + "Title": "urllib3: urllib3 Streaming API improperly handles highly compressed data", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66471", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37", + "https://linux.oracle.com/cve/CVE-2025-66471.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66471", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-7927-2", + "https://ubuntu.com/security/notices/USN-7927-3", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://ubuntu.com/security/notices/USN-8344-2", + "https://ubuntu.com/security/notices/USN-8344-3", + "https://www.cve.org/CVERecord?id=CVE-2025-66471", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T17:16:04.4Z", + "LastModifiedDate": "2026-06-17T09:56:53.65Z" + }, + { + "VulnerabilityID": "CVE-2026-21441", + "VendorIDs": [ + "GHSA-38jv-5279-wg99" + ], + "PkgName": "urllib3", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/urllib3-1.26.11.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@1.26.11", + "UID": "bdec38cefac9e3a1" + }, + "InstalledVersion": "1.26.11", + "FixedVersion": "2.6.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-21441", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:08ab4da006e0b8078e9185ba56ae81aeafea706ee647776c35412056796efcff", + "Title": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)", + "Description": "urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V3Score": 7.5, + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0981", + "https://access.redhat.com/errata/RHSA-2026:0990", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:1038", + "https://access.redhat.com/errata/RHSA-2026:1041", + "https://access.redhat.com/errata/RHSA-2026:1042", + "https://access.redhat.com/errata/RHSA-2026:1086", + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1088", + "https://access.redhat.com/errata/RHSA-2026:1089", + "https://access.redhat.com/errata/RHSA-2026:1166", + "https://access.redhat.com/errata/RHSA-2026:1168", + "https://access.redhat.com/errata/RHSA-2026:1176", + "https://access.redhat.com/errata/RHSA-2026:1224", + "https://access.redhat.com/errata/RHSA-2026:1226", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/errata/RHSA-2026:1240", + "https://access.redhat.com/errata/RHSA-2026:1241", + "https://access.redhat.com/errata/RHSA-2026:1254", + "https://access.redhat.com/errata/RHSA-2026:1485", + "https://access.redhat.com/errata/RHSA-2026:14877", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:1546", + "https://access.redhat.com/errata/RHSA-2026:1596", + "https://access.redhat.com/errata/RHSA-2026:1599", + "https://access.redhat.com/errata/RHSA-2026:1609", + "https://access.redhat.com/errata/RHSA-2026:1618", + "https://access.redhat.com/errata/RHSA-2026:1619", + "https://access.redhat.com/errata/RHSA-2026:1652", + "https://access.redhat.com/errata/RHSA-2026:1674", + "https://access.redhat.com/errata/RHSA-2026:1676", + "https://access.redhat.com/errata/RHSA-2026:1693", + "https://access.redhat.com/errata/RHSA-2026:1704", + "https://access.redhat.com/errata/RHSA-2026:1706", + "https://access.redhat.com/errata/RHSA-2026:1712", + "https://access.redhat.com/errata/RHSA-2026:1717", + "https://access.redhat.com/errata/RHSA-2026:1726", + "https://access.redhat.com/errata/RHSA-2026:1729", + "https://access.redhat.com/errata/RHSA-2026:1730", + "https://access.redhat.com/errata/RHSA-2026:1734", + "https://access.redhat.com/errata/RHSA-2026:1735", + "https://access.redhat.com/errata/RHSA-2026:1736", + "https://access.redhat.com/errata/RHSA-2026:17456", + "https://access.redhat.com/errata/RHSA-2026:17457", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17461", + "https://access.redhat.com/errata/RHSA-2026:17462", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:1791", + "https://access.redhat.com/errata/RHSA-2026:1792", + "https://access.redhat.com/errata/RHSA-2026:1793", + "https://access.redhat.com/errata/RHSA-2026:1794", + "https://access.redhat.com/errata/RHSA-2026:1803", + "https://access.redhat.com/errata/RHSA-2026:1805", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:1957", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2126", + "https://access.redhat.com/errata/RHSA-2026:2137", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2144", + "https://access.redhat.com/errata/RHSA-2026:2256", + "https://access.redhat.com/errata/RHSA-2026:2456", + "https://access.redhat.com/errata/RHSA-2026:2500", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:2563", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2717", + "https://access.redhat.com/errata/RHSA-2026:2718", + "https://access.redhat.com/errata/RHSA-2026:2723", + "https://access.redhat.com/errata/RHSA-2026:2728", + "https://access.redhat.com/errata/RHSA-2026:2760", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2764", + "https://access.redhat.com/errata/RHSA-2026:2765", + "https://access.redhat.com/errata/RHSA-2026:28043", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2911", + "https://access.redhat.com/errata/RHSA-2026:2919", + "https://access.redhat.com/errata/RHSA-2026:2924", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:2926", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:33154", + "https://access.redhat.com/errata/RHSA-2026:3406", + "https://access.redhat.com/errata/RHSA-2026:3444", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:44696", + "https://access.redhat.com/errata/RHSA-2026:51357", + "https://access.redhat.com/errata/RHSA-2026:5459", + "https://access.redhat.com/errata/RHSA-2026:6287", + "https://access.redhat.com/errata/RHSA-2026:6292", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8500", + "https://access.redhat.com/errata/RHSA-2026:8501", + "https://access.redhat.com/security/cve/CVE-2026-21441", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99", + "https://linux.oracle.com/cve/CVE-2026-21441.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-21441", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json", + "https://ubuntu.com/security/notices/USN-7955-1", + "https://ubuntu.com/security/notices/USN-7955-2", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2026-21441" + ], + "PublishedDate": "2026-01-07T22:15:44.04Z", + "LastModifiedDate": "2026-08-14T13:17:38.737Z" + }, + { + "VulnerabilityID": "CVE-2026-44431", + "VendorIDs": [ + "GHSA-qccp-gfcp-xxvc" + ], + "PkgName": "urllib3", + "PkgPath": "HiC-Pro-env/lib/python3.8/site-packages/urllib3-1.26.11.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@1.26.11", + "UID": "bdec38cefac9e3a1" + }, + "InstalledVersion": "1.26.11", + "FixedVersion": "2.7.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:75b6607856289468612924d9248d5dea6a417223da021608300a20aab89f3743", + "DiffID": "sha256:bc5bdce68640c9ca76933cbe13a64c3d277f79fd0213f54d02ed8dee81dc7e9b" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44431", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:dcfa6da0475265fda534dd44351c79f588299e996444acaa20c5c6e0c14026ac", + "Title": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers", + "Description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V3Score": 5.3, + "V40Score": 8.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:28158", + "https://access.redhat.com/errata/RHSA-2026:28159", + "https://access.redhat.com/security/cve/CVE-2026-44431", + "https://bugzilla.redhat.com/2477154", + "https://bugzilla.redhat.com/2477167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477154", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477167", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432", + "https://errata.almalinux.org/9/ALSA-2026-28159.html", + "https://errata.rockylinux.org/RLSA-2026:28158", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc", + "https://linux.oracle.com/cve/CVE-2026-44431.html", + "https://linux.oracle.com/errata/ELSA-2026-49927.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44431", + "https://ubuntu.com/security/notices/USN-8379-1", + "https://www.cve.org/CVERecord?id=CVE-2026-44431" + ], + "PublishedDate": "2026-05-13T16:16:57.15Z", + "LastModifiedDate": "2026-06-26T12:16:32.423Z" + } + ], + "vulnerability_count": 46 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 46 + } +} diff --git a/bfx/hicexplorer/trivy-scan-results.json b/bfx/hicexplorer/trivy-scan-results.json new file mode 100644 index 00000000..c08655ee --- /dev/null +++ b/bfx/hicexplorer/trivy-scan-results.json @@ -0,0 +1,2713 @@ +{ + "tool": "hicexplorer", + "scan_timestamp": "2026-08-16T17:06:10Z", + "workflow_run_id": "31960542324", + "versions": { + "3.7.6": { + "image": "ghcr.io/bundlecore/products/bfx/hicexplorer:3.7.6", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2025-6176", + "VendorIDs": [ + "GHSA-2qfp-q593-8484" + ], + "PkgName": "Brotli", + "PkgPath": "usr/local/lib/python3.12/site-packages/Brotli-1.1.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/brotli@1.1.0", + "UID": "a7d383a006e445a1" + }, + "InstalledVersion": "1.1.0", + "FixedVersion": "1.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-6176", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c0e03b04e6e34ecadb4022ab378d090d3e8d8e140a94e65e902f8f5e3dd8984a", + "Title": "Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS", + "Description": "Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:2042", + "https://access.redhat.com/security/cve/CVE-2025-6176", + "https://bugzilla.redhat.com/2408762", + "https://bugzilla.redhat.com/show_bug.cgi?id=2408762", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6176", + "https://errata.almalinux.org/9/ALSA-2026-2042.html", + "https://errata.rockylinux.org/RLSA-2026:2042", + "https://github.com/google/brotli", + "https://github.com/google/brotli/commit/67d78bc41db1a0d03f2e763497748f2f69946627", + "https://github.com/google/brotli/issues/1327", + "https://github.com/google/brotli/issues/1375", + "https://github.com/google/brotli/pull/1234", + "https://github.com/google/brotli/releases/tag/v1.2.0", + "https://github.com/scrapy/scrapy/commit/14737e91edc513967f516fc839cc9c8a4f8d91da", + "https://github.com/scrapy/scrapy/pull/7134", + "https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0", + "https://linux.oracle.com/cve/CVE-2025-6176.html", + "https://linux.oracle.com/errata/ELSA-2026-2389.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-6176", + "https://www.cve.org/CVERecord?id=CVE-2025-6176" + ], + "PublishedDate": "2025-10-31T00:15:37.333Z", + "LastModifiedDate": "2026-06-17T10:01:19.72Z" + }, + { + "VulnerabilityID": "CVE-2024-45857", + "VendorIDs": [ + "GHSA-8cm9-rrgc-4pcj" + ], + "PkgName": "cleanlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/cleanlab-2.6.6.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/cleanlab@2.6.6", + "UID": "e3a4fe2c2826dd12" + }, + "InstalledVersion": "2.6.6", + "Status": "affected", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-45857", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:bf5fefe43d5e0ed1e3f8be135d6c64a28f2ab2ce01dd68cef8ae7908f3a1fc27", + "Title": "Cleanlab Deserialization of Untrusted Data vulnerability", + "Description": "Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.8, + "V40Score": 8.6 + } + }, + "References": [ + "https://github.com/cleanlab/cleanlab", + "https://github.com/cleanlab/cleanlab/blob/v2.6.6/cleanlab/datalab/internal/serialize.py#L102-L138", + "https://hiddenlayer.com/sai-security-advisory/2024-09-cleanlab", + "https://hiddenlayer.com/sai-security-advisory/2024-09-cleanlab/", + "https://nvd.nist.gov/vuln/detail/CVE-2024-45857" + ], + "PublishedDate": "2024-09-12T13:15:16.227Z", + "LastModifiedDate": "2026-06-17T07:54:58.46Z" + }, + { + "VulnerabilityID": "CVE-2026-23949", + "VendorIDs": [ + "GHSA-58pv-8j8x-9vj2" + ], + "PkgName": "jaraco.context", + "PkgPath": "usr/local/lib/python3.12/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jaraco.context@5.3.0", + "UID": "be15c137ae35e354" + }, + "InstalledVersion": "5.3.0", + "FixedVersion": "6.1.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-23949", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:57973c34ca07d997146d68fa6f19a387e73789ffe4f3f8b2cbaec3802e1ae877", + "Title": "jaraco.context: jaraco.context: Path traversal via malicious tar archives", + "Description": "jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow attackers to extract files outside the intended extraction directory when malicious tar archives are processed. The strip_first_component filter splits the path on the first `/` and extracts the second component, while allowing `../` sequences. Paths like `dummy_dir/../../etc/passwd` become `../../etc/passwd`. Note that this suffers from a nested tarball attack as well with multi-level tar files such as `dummy_dir/inner.tar.gz`, where the inner.tar.gz includes a traversal `dummy_dir/../../config/.env` that also gets translated to `../../config/.env`. Version 6.1.0 contains a patch for the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 8.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 8.6 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-23949", + "https://github.com/jaraco/jaraco.context", + "https://github.com/jaraco/jaraco.context/blob/main/jaraco/context/__init__.py#L74-L91", + "https://github.com/jaraco/jaraco.context/commit/7b26a42b525735e4085d2e994e13802ea339d5f9", + "https://github.com/jaraco/jaraco.context/security/advisories/GHSA-58pv-8j8x-9vj2", + "https://github.com/pypa/setuptools/blob/main/setuptools/_vendor/jaraco/context.py#L55-L76", + "https://nvd.nist.gov/vuln/detail/CVE-2026-23949", + "https://ubuntu.com/security/notices/USN-7979-1", + "https://www.cve.org/CVERecord?id=CVE-2026-23949" + ], + "PublishedDate": "2026-01-20T01:15:57.723Z", + "LastModifiedDate": "2026-06-17T10:22:20.2Z" + }, + { + "VulnerabilityID": "CVE-2025-30167", + "VendorIDs": [ + "GHSA-33p9-3p43-82vq" + ], + "PkgName": "jupyter_core", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_core-5.7.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-core@5.7.2", + "UID": "abb9dc71f60bd5b8" + }, + "InstalledVersion": "5.7.2", + "FixedVersion": "5.8.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-30167", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:25ebca57509baa3fec9aab938ac6ec9976f600ac4a996172dcd632d24ef3f03a", + "Title": "Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability", + "Description": "Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users. Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected. Users should upgrade to Jupyter Core version 5.8.0 or later to receive a patch. Some other mitigations are available. As administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users; or as administrator, create the `%PROGRAMDATA%\\jupyter` directory with appropriately restrictive permissions; or as user or administrator, set the `%PROGRAMDATA%` environment variable to a directory with appropriately restrictive permissions (e.g. controlled by administrators _or_ the current user).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-427" + ], + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.3 + } + }, + "References": [ + "https://github.com/jupyter/jupyter_core", + "https://github.com/jupyter/jupyter_core/commit/5e8965600adda6b416692ce7e85ecb2bd814bd52", + "https://github.com/jupyter/jupyter_core/security/advisories/GHSA-33p9-3p43-82vq", + "https://nvd.nist.gov/vuln/detail/CVE-2025-30167" + ], + "PublishedDate": "2025-06-03T17:15:21.52Z", + "LastModifiedDate": "2026-06-17T09:08:17.083Z" + }, + { + "VulnerabilityID": "GHSA-6v7p-g79w-8964", + "PkgName": "msgpack", + "PkgPath": "usr/local/lib/python3.12/site-packages/msgpack-1.1.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/msgpack@1.1.0", + "UID": "cdb994b7ce2d2ab" + }, + "InstalledVersion": "1.1.0", + "FixedVersion": "1.2.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-6v7p-g79w-8964", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:173127c6f501a84e3d29851df97e870040091ec4d86c5cfdc908942cc0864dfe", + "Title": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error", + "Description": "### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.\n\nTherefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/msgpack/msgpack-python", + "https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d", + "https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1", + "https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964" + ], + "PublishedDate": "2026-06-19T21:42:55Z", + "LastModifiedDate": "2026-06-19T21:42:55Z" + }, + { + "VulnerabilityID": "CVE-2026-25990", + "VendorIDs": [ + "GHSA-cfh3-3jmp-rvhc" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25990", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:25f4f9eb4a1bf3b2c18c2c90879f0f3de70f3c1075dbe99640e234cac2bbb38f", + "Title": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image", + "Description": "Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/02/12/1", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:14873", + "https://access.redhat.com/errata/RHSA-2026:14874", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:28385", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:4128", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6308", + "https://access.redhat.com/errata/RHSA-2026:6309", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/security/cve/CVE-2026-25990", + "https://bugzilla.redhat.com/show_bug.cgi?id=2439170", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199", + "https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa", + "https://github.com/python-pillow/Pillow/pull/9427", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25990", + "https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json", + "https://ubuntu.com/security/notices/USN-8047-1", + "https://www.cve.org/CVERecord?id=CVE-2026-25990" + ], + "PublishedDate": "2026-02-11T21:16:20.67Z", + "LastModifiedDate": "2026-08-12T12:18:09.957Z" + }, + { + "VulnerabilityID": "CVE-2026-40192", + "VendorIDs": [ + "GHSA-whj4-6x5x-4v2j" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40192", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:19a420489352f3c54961752ebfb46870ee8b64b764a58e5c5880b3ecc39f183a", + "Title": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing", + "Description": "Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770", + "CWE-409" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:16008", + "https://access.redhat.com/errata/RHSA-2026:16009", + "https://access.redhat.com/errata/RHSA-2026:16030", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:17609", + "https://access.redhat.com/errata/RHSA-2026:17611", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22629", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24866", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:34366", + "https://access.redhat.com/errata/RHSA-2026:34368", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/security/cve/CVE-2026-40192", + "https://bugzilla.redhat.com/show_bug.cgi?id=2458856", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628", + "https://github.com/python-pillow/Pillow/pull/9521", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40192", + "https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json", + "https://ubuntu.com/security/notices/USN-8211-1", + "https://www.cve.org/CVERecord?id=CVE-2026-40192" + ], + "PublishedDate": "2026-04-15T23:16:10.053Z", + "LastModifiedDate": "2026-08-12T12:19:09.49Z" + }, + { + "VulnerabilityID": "CVE-2026-42311", + "VendorIDs": [ + "GHSA-pwv6-vv43-88gr" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42311", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3a4c28d55ac7347764ec551aece5857ee8b6585e2a8210048245b50ea6219f4d", + "Title": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing", + "Description": "Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42311", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea", + "https://github.com/python-pillow/Pillow/pull/9520", + "https://github.com/python-pillow/Pillow/releases/tag/12.2.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42311", + "https://ubuntu.com/security/notices/USN-8399-1", + "https://www.cve.org/CVERecord?id=CVE-2026-42311" + ], + "PublishedDate": "2026-05-09T06:16:10.43Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-54058", + "VendorIDs": [ + "GHSA-62p4-gmf7-7g93" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54058", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b3113623d011ed090b87b1e81657f955e98ad233a3d274bdf4f669af5d5f5b42", + "Title": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-54058", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d", + "https://github.com/python-pillow/Pillow/pull/9719", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93", + "https://linux.oracle.com/cve/CVE-2026-54058.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54058", + "https://www.cve.org/CVERecord?id=CVE-2026-54058" + ], + "PublishedDate": "2026-07-14T17:17:03.433Z", + "LastModifiedDate": "2026-08-06T15:46:05.867Z" + }, + { + "VulnerabilityID": "CVE-2026-54059", + "VendorIDs": [ + "GHSA-8v84-f9pq-wr9x" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54059", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:1ecb4152d837cf28276a4a9588337e77e4d7070f2cec4904a99201f95733ec73", + "Title": "python-pillow: Pillow: Denial of Service via crafted PCF font data", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54059", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2253.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x", + "https://linux.oracle.com/cve/CVE-2026-54059.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54059", + "https://www.cve.org/CVERecord?id=CVE-2026-54059" + ], + "PublishedDate": "2026-07-06T19:17:08.127Z", + "LastModifiedDate": "2026-07-07T18:58:26.73Z" + }, + { + "VulnerabilityID": "CVE-2026-54060", + "VendorIDs": [ + "GHSA-5x94-69rx-g8h2" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54060", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c7cfc6ae18393e226502237474a148e19ac6d4c4a9ffc74924a275b79d91fbb0", + "Title": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54060", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2", + "https://linux.oracle.com/cve/CVE-2026-54060.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54060", + "https://www.cve.org/CVERecord?id=CVE-2026-54060" + ], + "PublishedDate": "2026-07-06T19:17:08.27Z", + "LastModifiedDate": "2026-07-07T18:58:45.827Z" + }, + { + "VulnerabilityID": "CVE-2026-55379", + "VendorIDs": [ + "GHSA-45hq-cxwh-f6vc" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55379", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:17cd5097f469b0a4114b48d0eafdf4eb031bcb62ded6072b83cbba3fe4a346f1", + "Title": "python-pillow: Pillow: Denial of Service via crafted BDF font file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55379", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2255.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc", + "https://linux.oracle.com/cve/CVE-2026-55379.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55379", + "https://www.cve.org/CVERecord?id=CVE-2026-55379" + ], + "PublishedDate": "2026-07-06T19:17:08.577Z", + "LastModifiedDate": "2026-07-07T18:59:01.817Z" + }, + { + "VulnerabilityID": "CVE-2026-55380", + "VendorIDs": [ + "GHSA-phj9-mv4w-65pm" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55380", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:ddfa7c90a5a2704a101f6600e41a92e47652f114f5c136623e886cdde90ac994", + "Title": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55380", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2256.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm", + "https://linux.oracle.com/cve/CVE-2026-55380.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55380", + "https://www.cve.org/CVERecord?id=CVE-2026-55380" + ], + "PublishedDate": "2026-07-06T19:17:08.703Z", + "LastModifiedDate": "2026-07-07T18:58:54.647Z" + }, + { + "VulnerabilityID": "CVE-2026-59197", + "VendorIDs": [ + "GHSA-xj96-63gp-2gmr" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59197", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:08af370da80c20d9f4e0cae79b93288869ea96e3ea468bb2092cc5cc3fc660e2", + "Title": "Pillow: Pillow: Native heap out-of-bounds write", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-59197", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1", + "https://github.com/python-pillow/Pillow/pull/9695", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr", + "https://linux.oracle.com/cve/CVE-2026-59197.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59197", + "https://www.cve.org/CVERecord?id=CVE-2026-59197" + ], + "PublishedDate": "2026-07-14T17:17:14.487Z", + "LastModifiedDate": "2026-07-21T19:17:11.907Z" + }, + { + "VulnerabilityID": "CVE-2026-59199", + "VendorIDs": [ + "GHSA-6r8x-57c9-28j4" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59199", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:99a8bcfc130c2925e10da4d7e62a48c000319e6cbefb55f10fe612daec725553", + "Title": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59199", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3451.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b", + "https://github.com/python-pillow/Pillow/pull/9703", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59199", + "https://www.cve.org/CVERecord?id=CVE-2026-59199" + ], + "PublishedDate": "2026-07-14T16:17:01.937Z", + "LastModifiedDate": "2026-07-15T16:16:49.487Z" + }, + { + "VulnerabilityID": "CVE-2026-59200", + "VendorIDs": [ + "GHSA-jjj6-mw9f-p565" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59200", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:53901174cc75b3d34dd90badb5460b4a5d6d3d683a71aec9447a29929a456069", + "Title": "Pillow: Pillow: Denial of service via crafted PDF stream", + "Description": "Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59200", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09", + "https://github.com/python-pillow/Pillow/pull/9718", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59200", + "https://www.cve.org/CVERecord?id=CVE-2026-59200" + ], + "PublishedDate": "2026-07-14T17:17:14.62Z", + "LastModifiedDate": "2026-07-21T15:52:40.107Z" + }, + { + "VulnerabilityID": "CVE-2026-59204", + "VendorIDs": [ + "GHSA-vjc4-5qp5-m44j" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59204", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:d9d5b14e2ac7123fd92015962591907d63ca0f6d3500e08ef10899802732d1ba", + "Title": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image", + "Description": "Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59204", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca", + "https://github.com/python-pillow/Pillow/pull/9704", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59204", + "https://www.cve.org/CVERecord?id=CVE-2026-59204" + ], + "PublishedDate": "2026-07-14T16:17:02.227Z", + "LastModifiedDate": "2026-07-21T19:17:12.02Z" + }, + { + "VulnerabilityID": "CVE-2026-59205", + "VendorIDs": [ + "GHSA-9hw9-ch79-4vh6" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.0.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.0.0", + "UID": "ee50f5cb01f4b737" + }, + "InstalledVersion": "11.0.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59205", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:310307220dda66bddd370e6afe80a9f199aba3e5270f67c718ad55b89ebccc0b", + "Title": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59205", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3453.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721", + "https://github.com/python-pillow/Pillow/pull/9715", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59205", + "https://www.cve.org/CVERecord?id=CVE-2026-59205" + ], + "PublishedDate": "2026-07-14T16:17:02.37Z", + "LastModifiedDate": "2026-07-14T20:09:27.77Z" + }, + { + "VulnerabilityID": "CVE-2026-25087", + "VendorIDs": [ + "GHSA-rgxp-2hwp-jwgg" + ], + "PkgName": "pyarrow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pyarrow-18.1.0-py3.12.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/pyarrow@18.1.0", + "UID": "836a03c731e92497" + }, + "InstalledVersion": "18.1.0", + "FixedVersion": "23.0.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25087", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:7591dd9ad62748d62c0b7f75e48a6721ba1710212ad09980fa5e0a04b2c25e60", + "Title": "apache-arrow: Apache Arrow C++: Denial of Service via Use After Free vulnerability when reading IPC files", + "Description": "Use After Free vulnerability in Apache Arrow C++.\n\nThis issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data). Depending on the number of variadic buffers in a record batch column and on the temporal sequence of multi-threaded IO, a write to a dangling pointer could occur. The value (a `std::shared_ptr` object) that is written to the dangling pointer is not under direct control of the attacker.\n\nPre-buffering is disabled by default but can be enabled using a specific C++ API call (`RecordBatchFileReader::PreBufferMetadata`). The functionality is not exposed in language bindings (Python, Ruby, C GLib), so these bindings are not vulnerable.\n\nThe most likely consequence of this issue would be random crashes or memory corruption when reading specific kinds of IPC files. If the application allows ingesting IPC files from untrusted sources, this could plausibly be exploited for denial of service. Inducing more targeted kinds of misbehavior (such as confidential data extraction from the running process) depends on memory allocation and multi-threaded IO temporal patterns that are unlikely to be easily controlled by an attacker.\n\nAdvice for users of Arrow C++:\n\n1. check whether you enable pre-buffering on the IPC file reader (using `RecordBatchFileReader::PreBufferMetadata`)\n\n2. if so, either disable pre-buffering (which may have adverse performance consequences), or switch to Arrow 23.0.1 which is not vulnerable", + "Severity": "HIGH", + "CweIDs": [ + "CWE-416" + ], + "VendorSeverity": { + "azure": 2, + "ghsa": 3, + "julia": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7 + }, + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", + "V3Score": 5.3 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/02/17/4", + "https://access.redhat.com/security/cve/CVE-2026-25087", + "https://github.com/advisories/GHSA-rgxp-2hwp-jwgg", + "https://github.com/apache/arrow", + "https://github.com/apache/arrow/pull/48925", + "https://github.com/pypa/advisory-database/tree/main/vulns/pyarrow/PYSEC-2026-113.yaml", + "https://lists.apache.org/thread/mpm4ld1qony30tchfpjtk5b11tcyvmwh", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25087", + "https://www.cve.org/CVERecord?id=CVE-2026-25087" + ], + "PublishedDate": "2026-02-17T14:16:01.947Z", + "LastModifiedDate": "2026-06-17T10:24:05.973Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgName": "setuptools", + "PkgPath": "usr/local/lib/python3.12/site-packages/setuptools-75.6.0-py3.9.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@75.6.0", + "UID": "c0dfef82504cedd4" + }, + "InstalledVersion": "75.6.0", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:aae7cfa808caa8a9a0bc4f420d7dca2dc5ed0652600bc8f1fd1f7e7ada3ef396", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:13578", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/9/ALSA-2025-13578.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + }, + { + "VulnerabilityID": "CVE-2025-47287", + "VendorIDs": [ + "GHSA-7cx3-6m66-7c5m" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.2", + "UID": "2fc5c6a65e7374e6" + }, + "InstalledVersion": "6.4.2", + "FixedVersion": "6.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47287", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:377db00c7ceb5dabb95f9a4d645573e81334d078fa2e12f3c0a8e60e9ef2f6de", + "Title": "tornado: Tornado Multipart Form-Data Denial of Service", + "Description": "Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "ghsa": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:8136", + "https://access.redhat.com/security/cve/CVE-2025-47287", + "https://bugzilla.redhat.com/2366703", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366703", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47287", + "https://errata.almalinux.org/9/ALSA-2025-8136.html", + "https://errata.rockylinux.org/RLSA-2025:8136", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/b39b892bf78fe8fea01dd45199aa88307e7162f3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5m", + "https://linux.oracle.com/cve/CVE-2025-47287.html", + "https://linux.oracle.com/errata/ELSA-2025-8664.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00038.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47287", + "https://ubuntu.com/security/notices/USN-7547-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47287" + ], + "PublishedDate": "2025-05-15T22:15:18.827Z", + "LastModifiedDate": "2026-06-17T09:27:40.32Z" + }, + { + "VulnerabilityID": "CVE-2025-67725", + "VendorIDs": [ + "GHSA-c98p-7wgm-6p64" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.2", + "UID": "2fc5c6a65e7374e6" + }, + "InstalledVersion": "6.4.2", + "FixedVersion": "6.5.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-67725", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:0740d6c6d4ea0ebccd2ba3b57dcec6f5e161a1a6f83cbb35dd1f2073ed9bca66", + "Title": "tornado: Tornado Quadratic DoS via Repeated Header Coalescing", + "Description": "Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS). Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if max_header_size has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0930", + "https://access.redhat.com/security/cve/CVE-2025-67725", + "https://bugzilla.redhat.com/2421722", + "https://bugzilla.redhat.com/2421733", + "https://errata.almalinux.org/8/ALSA-2026-0930.html", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-266.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c98p-7wgm-6p64", + "https://linux.oracle.com/cve/CVE-2025-67725.html", + "https://linux.oracle.com/errata/ELSA-2026-0930.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-67725", + "https://ubuntu.com/security/notices/USN-7950-1", + "https://www.cve.org/CVERecord?id=CVE-2025-67725" + ], + "PublishedDate": "2025-12-12T06:15:41.38Z", + "LastModifiedDate": "2026-06-17T09:58:02.337Z" + }, + { + "VulnerabilityID": "CVE-2025-67726", + "VendorIDs": [ + "GHSA-jhmp-mqwm-3gq8" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.2", + "UID": "2fc5c6a65e7374e6" + }, + "InstalledVersion": "6.4.2", + "FixedVersion": "6.5.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-67726", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f781da308a05592d879448d85407b5d619b1ca107647956a180f464114d22be3", + "Title": "tornado: Tornado Quadratic DoS via Crafted Multipart Parameters", + "Description": "Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.py is used to parse specific HTTP header values, such as those in multipart/form-data and repeatedly calls string.count() within a nested loop while processing quoted semicolons. If an attacker sends a request with a large number of maliciously crafted parameters in a Content-Disposition header, the server's CPU usage increases quadratically (O(n²)) during parsing. Due to Tornado's single event loop architecture, a single malicious request can cause the entire server to become unresponsive for an extended period. This issue is fixed in version 6.5.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-834" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0930", + "https://access.redhat.com/security/cve/CVE-2025-67726", + "https://bugzilla.redhat.com/2421722", + "https://bugzilla.redhat.com/2421733", + "https://errata.almalinux.org/8/ALSA-2026-0930.html", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-267.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-jhmp-mqwm-3gq8", + "https://linux.oracle.com/cve/CVE-2025-67726.html", + "https://linux.oracle.com/errata/ELSA-2026-0930.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-67726", + "https://ubuntu.com/security/notices/USN-7950-1", + "https://www.cve.org/CVERecord?id=CVE-2025-67726" + ], + "PublishedDate": "2025-12-12T07:15:44.92Z", + "LastModifiedDate": "2026-06-17T09:58:02.44Z" + }, + { + "VulnerabilityID": "CVE-2026-31958", + "VendorIDs": [ + "GHSA-qjxf-f2mg-c6mc" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.2", + "UID": "2fc5c6a65e7374e6" + }, + "InstalledVersion": "6.4.2", + "FixedVersion": "6.5.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-31958", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:811f75943dfa6858203cd5de228c564b850e3db8a0c8cdcc1477543f447aa516", + "Title": "tornado-python: Tornado: Denial of Service via large multipart bodies", + "Description": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:19189", + "https://access.redhat.com/security/cve/CVE-2026-31958", + "https://bugzilla.redhat.com/2446765", + "https://bugzilla.redhat.com/2454716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", + "https://bugzilla.redhat.com/show_bug.cgi?id=2454716", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31958", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35536", + "https://errata.almalinux.org/9/ALSA-2026-19189.html", + "https://errata.rockylinux.org/RLSA-2026:19189", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2026-140.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc", + "https://linux.oracle.com/cve/CVE-2026-31958.html", + "https://linux.oracle.com/errata/ELSA-2026-8093.html", + "https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-31958", + "https://ubuntu.com/security/notices/USN-8198-1", + "https://ubuntu.com/security/notices/USN-8198-2", + "https://www.cve.org/CVERecord?id=CVE-2026-31958" + ], + "PublishedDate": "2026-03-11T20:16:16.617Z", + "LastModifiedDate": "2026-06-17T10:34:50.473Z" + }, + { + "VulnerabilityID": "CVE-2026-35536", + "VendorIDs": [ + "GHSA-fqwm-6jpj-5wxc" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.2", + "UID": "2fc5c6a65e7374e6" + }, + "InstalledVersion": "6.4.2", + "FixedVersion": "6.5.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-35536", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:da5522975af23e9cbf8ad921b9833170cbb05bf50bff8c0981ebdf3005c16bb0", + "Title": "tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments", + "Description": "In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-159" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "photon": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N", + "V3Score": 7.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", + "V3Score": 5.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:19189", + "https://access.redhat.com/security/cve/CVE-2026-35536", + "https://bugzilla.redhat.com/2446765", + "https://bugzilla.redhat.com/2454716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", + "https://bugzilla.redhat.com/show_bug.cgi?id=2454716", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31958", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35536", + "https://errata.almalinux.org/9/ALSA-2026-19189.html", + "https://errata.rockylinux.org/RLSA-2026:19189", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7", + "https://linux.oracle.com/cve/CVE-2026-35536.html", + "https://linux.oracle.com/errata/ELSA-2026-24342.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-35536", + "https://ubuntu.com/security/notices/USN-8198-1", + "https://ubuntu.com/security/notices/USN-8198-2", + "https://www.cve.org/CVERecord?id=CVE-2026-35536" + ], + "PublishedDate": "2026-04-03T04:16:53.55Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-49853", + "VendorIDs": [ + "GHSA-3x9g-8vmp-wqvf" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.2", + "UID": "2fc5c6a65e7374e6" + }, + "InstalledVersion": "6.4.2", + "FixedVersion": "6.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49853", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:8f8266044011f05f109c9b51349c35ef69e7553fb10da3200e09b44865e76837", + "Title": "Tornado is a Python web framework and asynchronous networking library. ...", + "Description": "Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "photon": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 7.7 + } + }, + "References": [ + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/aba2569f7ed7a6bdbef816658fb6b7182531b751", + "https://github.com/tornadoweb/tornado/pull/3626", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.6", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf" + ], + "PublishedDate": "2026-07-14T21:17:02.13Z", + "LastModifiedDate": "2026-07-21T16:17:13.477Z" + }, + { + "VulnerabilityID": "CVE-2026-49855", + "VendorIDs": [ + "GHSA-mgf9-4vpg-hj56" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.2", + "UID": "2fc5c6a65e7374e6" + }, + "InstalledVersion": "6.4.2", + "FixedVersion": "6.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49855", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:07956059da95fc9e6e93ac324a8d9bb4f05f1a810265a180dbd123c81dc3aa40", + "Title": "Tornado is a Python web framework and asynchronous networking library. ...", + "Description": "Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "photon": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff", + "https://github.com/tornadoweb/tornado/pull/3626", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56" + ], + "PublishedDate": "2026-07-14T21:17:02.437Z", + "LastModifiedDate": "2026-07-16T16:19:10.69Z" + }, + { + "VulnerabilityID": "CVE-2025-66418", + "VendorIDs": [ + "GHSA-gm62-xv2j-4w53" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.2.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.3", + "UID": "1964cadfacdef1dd" + }, + "InstalledVersion": "2.2.3", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66418", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:e23be0cd59102afa574a3c2b33f1efaf345ba5dfe7f4805bfd5fbe03804d131f", + "Title": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66418", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53", + "https://linux.oracle.com/cve/CVE-2025-66418.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66418", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://www.cve.org/CVERecord?id=CVE-2025-66418", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T16:15:51.053Z", + "LastModifiedDate": "2026-06-17T09:56:48.383Z" + }, + { + "VulnerabilityID": "CVE-2025-66471", + "VendorIDs": [ + "GHSA-2xpw-w6gg-jr37" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.2.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.3", + "UID": "1964cadfacdef1dd" + }, + "InstalledVersion": "2.2.3", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66471", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f8a46f8ad39c89e6dfe82f3c7ac84679026d88a349c7e2e7bc2e28c9570ea6bc", + "Title": "urllib3: urllib3 Streaming API improperly handles highly compressed data", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66471", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37", + "https://linux.oracle.com/cve/CVE-2025-66471.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66471", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-7927-2", + "https://ubuntu.com/security/notices/USN-7927-3", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://ubuntu.com/security/notices/USN-8344-2", + "https://ubuntu.com/security/notices/USN-8344-3", + "https://www.cve.org/CVERecord?id=CVE-2025-66471", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T17:16:04.4Z", + "LastModifiedDate": "2026-06-17T09:56:53.65Z" + }, + { + "VulnerabilityID": "CVE-2026-21441", + "VendorIDs": [ + "GHSA-38jv-5279-wg99" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.2.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.3", + "UID": "1964cadfacdef1dd" + }, + "InstalledVersion": "2.2.3", + "FixedVersion": "2.6.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-21441", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:fc999484a4766635b96d83f60c720e291dff5ae6073900289313b00f426767c1", + "Title": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)", + "Description": "urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V3Score": 7.5, + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0981", + "https://access.redhat.com/errata/RHSA-2026:0990", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:1038", + "https://access.redhat.com/errata/RHSA-2026:1041", + "https://access.redhat.com/errata/RHSA-2026:1042", + "https://access.redhat.com/errata/RHSA-2026:1086", + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1088", + "https://access.redhat.com/errata/RHSA-2026:1089", + "https://access.redhat.com/errata/RHSA-2026:1166", + "https://access.redhat.com/errata/RHSA-2026:1168", + "https://access.redhat.com/errata/RHSA-2026:1176", + "https://access.redhat.com/errata/RHSA-2026:1224", + "https://access.redhat.com/errata/RHSA-2026:1226", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/errata/RHSA-2026:1240", + "https://access.redhat.com/errata/RHSA-2026:1241", + "https://access.redhat.com/errata/RHSA-2026:1254", + "https://access.redhat.com/errata/RHSA-2026:1485", + "https://access.redhat.com/errata/RHSA-2026:14877", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:1546", + "https://access.redhat.com/errata/RHSA-2026:1596", + "https://access.redhat.com/errata/RHSA-2026:1599", + "https://access.redhat.com/errata/RHSA-2026:1609", + "https://access.redhat.com/errata/RHSA-2026:1618", + "https://access.redhat.com/errata/RHSA-2026:1619", + "https://access.redhat.com/errata/RHSA-2026:1652", + "https://access.redhat.com/errata/RHSA-2026:1674", + "https://access.redhat.com/errata/RHSA-2026:1676", + "https://access.redhat.com/errata/RHSA-2026:1693", + "https://access.redhat.com/errata/RHSA-2026:1704", + "https://access.redhat.com/errata/RHSA-2026:1706", + "https://access.redhat.com/errata/RHSA-2026:1712", + "https://access.redhat.com/errata/RHSA-2026:1717", + "https://access.redhat.com/errata/RHSA-2026:1726", + "https://access.redhat.com/errata/RHSA-2026:1729", + "https://access.redhat.com/errata/RHSA-2026:1730", + "https://access.redhat.com/errata/RHSA-2026:1734", + "https://access.redhat.com/errata/RHSA-2026:1735", + "https://access.redhat.com/errata/RHSA-2026:1736", + "https://access.redhat.com/errata/RHSA-2026:17456", + "https://access.redhat.com/errata/RHSA-2026:17457", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17461", + "https://access.redhat.com/errata/RHSA-2026:17462", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:1791", + "https://access.redhat.com/errata/RHSA-2026:1792", + "https://access.redhat.com/errata/RHSA-2026:1793", + "https://access.redhat.com/errata/RHSA-2026:1794", + "https://access.redhat.com/errata/RHSA-2026:1803", + "https://access.redhat.com/errata/RHSA-2026:1805", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:1957", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2126", + "https://access.redhat.com/errata/RHSA-2026:2137", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2144", + "https://access.redhat.com/errata/RHSA-2026:2256", + "https://access.redhat.com/errata/RHSA-2026:2456", + "https://access.redhat.com/errata/RHSA-2026:2500", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:2563", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2717", + "https://access.redhat.com/errata/RHSA-2026:2718", + "https://access.redhat.com/errata/RHSA-2026:2723", + "https://access.redhat.com/errata/RHSA-2026:2728", + "https://access.redhat.com/errata/RHSA-2026:2760", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2764", + "https://access.redhat.com/errata/RHSA-2026:2765", + "https://access.redhat.com/errata/RHSA-2026:28043", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2911", + "https://access.redhat.com/errata/RHSA-2026:2919", + "https://access.redhat.com/errata/RHSA-2026:2924", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:2926", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:33154", + "https://access.redhat.com/errata/RHSA-2026:3406", + "https://access.redhat.com/errata/RHSA-2026:3444", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:44696", + "https://access.redhat.com/errata/RHSA-2026:51357", + "https://access.redhat.com/errata/RHSA-2026:5459", + "https://access.redhat.com/errata/RHSA-2026:6287", + "https://access.redhat.com/errata/RHSA-2026:6292", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8500", + "https://access.redhat.com/errata/RHSA-2026:8501", + "https://access.redhat.com/security/cve/CVE-2026-21441", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99", + "https://linux.oracle.com/cve/CVE-2026-21441.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-21441", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json", + "https://ubuntu.com/security/notices/USN-7955-1", + "https://ubuntu.com/security/notices/USN-7955-2", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2026-21441" + ], + "PublishedDate": "2026-01-07T22:15:44.04Z", + "LastModifiedDate": "2026-08-14T13:17:38.737Z" + }, + { + "VulnerabilityID": "CVE-2026-44431", + "VendorIDs": [ + "GHSA-qccp-gfcp-xxvc" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.2.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.3", + "UID": "1964cadfacdef1dd" + }, + "InstalledVersion": "2.2.3", + "FixedVersion": "2.7.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44431", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:db88f31e40d72841da31293f2e0659f6bd8364eb5d386d548e7129fc30eea28a", + "Title": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers", + "Description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V3Score": 5.3, + "V40Score": 8.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:28158", + "https://access.redhat.com/errata/RHSA-2026:28159", + "https://access.redhat.com/security/cve/CVE-2026-44431", + "https://bugzilla.redhat.com/2477154", + "https://bugzilla.redhat.com/2477167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477154", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477167", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432", + "https://errata.almalinux.org/9/ALSA-2026-28159.html", + "https://errata.rockylinux.org/RLSA-2026:28158", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc", + "https://linux.oracle.com/cve/CVE-2026-44431.html", + "https://linux.oracle.com/errata/ELSA-2026-49927.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44431", + "https://ubuntu.com/security/notices/USN-8379-1", + "https://www.cve.org/CVERecord?id=CVE-2026-44431" + ], + "PublishedDate": "2026-05-13T16:16:57.15Z", + "LastModifiedDate": "2026-06-26T12:16:32.423Z" + }, + { + "VulnerabilityID": "CVE-2026-24049", + "VendorIDs": [ + "GHSA-8rrh-rw8j-w5fx" + ], + "PkgName": "wheel", + "PkgPath": "usr/local/lib/python3.12/site-packages/setuptools/_vendor/wheel-0.43.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/wheel@0.43.0", + "UID": "ad762306bd82926c" + }, + "InstalledVersion": "0.43.0", + "FixedVersion": "0.46.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-24049", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b5560a7138e0df95714ae15b55359d425488d6a7e27df56a75f1141a80e4e5c5", + "Title": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking", + "Description": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22", + "CWE-732" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", + "V3Score": 5.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:1902", + "https://access.redhat.com/errata/RHSA-2026:1939", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:2090", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2675", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2694", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2710", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2823", + "https://access.redhat.com/errata/RHSA-2026:2865", + "https://access.redhat.com/errata/RHSA-2026:2866", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5119", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6555", + "https://access.redhat.com/errata/RHSA-2026:6562", + "https://access.redhat.com/errata/RHSA-2026:6565", + "https://access.redhat.com/errata/RHSA-2026:7250", + "https://access.redhat.com/security/cve/CVE-2026-24049", + "https://bugzilla.redhat.com/2431959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2431959", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24049", + "https://errata.almalinux.org/9/ALSA-2026-1939.html", + "https://errata.rockylinux.org/RLSA-2026:1939", + "https://github.com/pypa/wheel", + "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef", + "https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e", + "https://github.com/pypa/wheel/releases/tag/0.46.2", + "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx", + "https://linux.oracle.com/cve/CVE-2026-24049.html", + "https://linux.oracle.com/errata/ELSA-2026-2090.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-24049", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json", + "https://ubuntu.com/security/notices/USN-8221-1", + "https://www.cve.org/CVERecord?id=CVE-2026-24049" + ], + "PublishedDate": "2026-01-22T05:16:23.157Z", + "LastModifiedDate": "2026-08-12T12:17:55.967Z" + }, + { + "VulnerabilityID": "CVE-2026-24049", + "VendorIDs": [ + "GHSA-8rrh-rw8j-w5fx" + ], + "PkgName": "wheel", + "PkgPath": "usr/local/lib/python3.12/site-packages/wheel-0.45.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/wheel@0.45.1", + "UID": "36e27261436629ac" + }, + "InstalledVersion": "0.45.1", + "FixedVersion": "0.46.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:b00f8b761f69ac70b6f4270a1dec7e949a1ad6f0f6da8708839dd981af079af1", + "DiffID": "sha256:4dbf7c4c5480a028c0272fe4e330ac36a6a80fceb5ac520003d78105853870b6" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-24049", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b5560a7138e0df95714ae15b55359d425488d6a7e27df56a75f1141a80e4e5c5", + "Title": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking", + "Description": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22", + "CWE-732" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", + "V3Score": 5.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:1902", + "https://access.redhat.com/errata/RHSA-2026:1939", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:2090", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2675", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2694", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2710", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2823", + "https://access.redhat.com/errata/RHSA-2026:2865", + "https://access.redhat.com/errata/RHSA-2026:2866", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5119", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6555", + "https://access.redhat.com/errata/RHSA-2026:6562", + "https://access.redhat.com/errata/RHSA-2026:6565", + "https://access.redhat.com/errata/RHSA-2026:7250", + "https://access.redhat.com/security/cve/CVE-2026-24049", + "https://bugzilla.redhat.com/2431959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2431959", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24049", + "https://errata.almalinux.org/9/ALSA-2026-1939.html", + "https://errata.rockylinux.org/RLSA-2026:1939", + "https://github.com/pypa/wheel", + "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef", + "https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e", + "https://github.com/pypa/wheel/releases/tag/0.46.2", + "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx", + "https://linux.oracle.com/cve/CVE-2026-24049.html", + "https://linux.oracle.com/errata/ELSA-2026-2090.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-24049", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json", + "https://ubuntu.com/security/notices/USN-8221-1", + "https://www.cve.org/CVERecord?id=CVE-2026-24049" + ], + "PublishedDate": "2026-01-22T05:16:23.157Z", + "LastModifiedDate": "2026-08-12T12:17:55.967Z" + } + ], + "vulnerability_count": 33 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 33 + } +} diff --git a/bfx/hmmer/trivy-scan-results.json b/bfx/hmmer/trivy-scan-results.json new file mode 100644 index 00000000..de6f0be2 --- /dev/null +++ b/bfx/hmmer/trivy-scan-results.json @@ -0,0 +1,16 @@ +{ + "tool": "hmmer", + "scan_timestamp": "2026-08-16T17:06:50Z", + "workflow_run_id": "31960542324", + "versions": { + "3.4": { + "image": "ghcr.io/bundlecore/products/bfx/hmmer:3.4", + "vulnerabilities": [], + "vulnerability_count": 0 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/homer2/trivy-scan-results.json b/bfx/homer2/trivy-scan-results.json new file mode 100644 index 00000000..0c0a94cc --- /dev/null +++ b/bfx/homer2/trivy-scan-results.json @@ -0,0 +1,16 @@ +{ + "tool": "homer2", + "scan_timestamp": "2026-08-16T17:06:54Z", + "workflow_run_id": "31960542324", + "versions": { + "5.1": { + "image": "ghcr.io/bundlecore/products/bfx/homer2:5.1", + "vulnerabilities": [], + "vulnerability_count": 0 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/homopolish/trivy-scan-results.json b/bfx/homopolish/trivy-scan-results.json new file mode 100644 index 00000000..b992d8e6 --- /dev/null +++ b/bfx/homopolish/trivy-scan-results.json @@ -0,0 +1,936 @@ +{ + "tool": "homopolish", + "scan_timestamp": "2026-08-16T17:06:59Z", + "workflow_run_id": "31960542324", + "versions": { + "0.4.2": { + "image": "ghcr.io/bundlecore/products/bfx/homopolish:0.4.2", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2025-6176", + "VendorIDs": [ + "GHSA-2qfp-q593-8484" + ], + "PkgName": "Brotli", + "PkgPath": "usr/local/lib/python3.12/site-packages/brotli-1.1.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/brotli@1.1.0", + "UID": "b8f73fa3fb3ec85" + }, + "InstalledVersion": "1.1.0", + "FixedVersion": "1.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-6176", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:e3f57b255b61ce20a2787c1ee356709b2fcc7ce73cc0d81a580ad3e9352d6f14", + "Title": "Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS", + "Description": "Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:2042", + "https://access.redhat.com/security/cve/CVE-2025-6176", + "https://bugzilla.redhat.com/2408762", + "https://bugzilla.redhat.com/show_bug.cgi?id=2408762", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6176", + "https://errata.almalinux.org/9/ALSA-2026-2042.html", + "https://errata.rockylinux.org/RLSA-2026:2042", + "https://github.com/google/brotli", + "https://github.com/google/brotli/commit/67d78bc41db1a0d03f2e763497748f2f69946627", + "https://github.com/google/brotli/issues/1327", + "https://github.com/google/brotli/issues/1375", + "https://github.com/google/brotli/pull/1234", + "https://github.com/google/brotli/releases/tag/v1.2.0", + "https://github.com/scrapy/scrapy/commit/14737e91edc513967f516fc839cc9c8a4f8d91da", + "https://github.com/scrapy/scrapy/pull/7134", + "https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0", + "https://linux.oracle.com/cve/CVE-2025-6176.html", + "https://linux.oracle.com/errata/ELSA-2026-2389.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-6176", + "https://www.cve.org/CVERecord?id=CVE-2025-6176" + ], + "PublishedDate": "2025-10-31T00:15:37.333Z", + "LastModifiedDate": "2026-06-17T10:01:19.72Z" + }, + { + "VulnerabilityID": "CVE-2026-23949", + "VendorIDs": [ + "GHSA-58pv-8j8x-9vj2" + ], + "PkgName": "jaraco.context", + "PkgPath": "usr/local/lib/python3.12/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jaraco.context@5.3.0", + "UID": "be15c137ae35e354" + }, + "InstalledVersion": "5.3.0", + "FixedVersion": "6.1.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-23949", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:1a94cb15026ea71cee63c77d0b6e77513cb06bc5f3bc71ce7ac19267b34dbfb6", + "Title": "jaraco.context: jaraco.context: Path traversal via malicious tar archives", + "Description": "jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow attackers to extract files outside the intended extraction directory when malicious tar archives are processed. The strip_first_component filter splits the path on the first `/` and extracts the second component, while allowing `../` sequences. Paths like `dummy_dir/../../etc/passwd` become `../../etc/passwd`. Note that this suffers from a nested tarball attack as well with multi-level tar files such as `dummy_dir/inner.tar.gz`, where the inner.tar.gz includes a traversal `dummy_dir/../../config/.env` that also gets translated to `../../config/.env`. Version 6.1.0 contains a patch for the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 8.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 8.6 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-23949", + "https://github.com/jaraco/jaraco.context", + "https://github.com/jaraco/jaraco.context/blob/main/jaraco/context/__init__.py#L74-L91", + "https://github.com/jaraco/jaraco.context/commit/7b26a42b525735e4085d2e994e13802ea339d5f9", + "https://github.com/jaraco/jaraco.context/security/advisories/GHSA-58pv-8j8x-9vj2", + "https://github.com/pypa/setuptools/blob/main/setuptools/_vendor/jaraco/context.py#L55-L76", + "https://nvd.nist.gov/vuln/detail/CVE-2026-23949", + "https://ubuntu.com/security/notices/USN-7979-1", + "https://www.cve.org/CVERecord?id=CVE-2026-23949" + ], + "PublishedDate": "2026-01-20T01:15:57.723Z", + "LastModifiedDate": "2026-06-17T10:22:20.2Z" + }, + { + "VulnerabilityID": "CVE-2026-25087", + "VendorIDs": [ + "GHSA-rgxp-2hwp-jwgg" + ], + "PkgName": "pyarrow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pyarrow-21.0.0-py3.12.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/pyarrow@21.0.0", + "UID": "ec1274827a17318d" + }, + "InstalledVersion": "21.0.0", + "FixedVersion": "23.0.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25087", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:26c8261d387babc8c6290d97b77340009971b3bb1542d7ef346e479b1c198754", + "Title": "apache-arrow: Apache Arrow C++: Denial of Service via Use After Free vulnerability when reading IPC files", + "Description": "Use After Free vulnerability in Apache Arrow C++.\n\nThis issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data). Depending on the number of variadic buffers in a record batch column and on the temporal sequence of multi-threaded IO, a write to a dangling pointer could occur. The value (a `std::shared_ptr` object) that is written to the dangling pointer is not under direct control of the attacker.\n\nPre-buffering is disabled by default but can be enabled using a specific C++ API call (`RecordBatchFileReader::PreBufferMetadata`). The functionality is not exposed in language bindings (Python, Ruby, C GLib), so these bindings are not vulnerable.\n\nThe most likely consequence of this issue would be random crashes or memory corruption when reading specific kinds of IPC files. If the application allows ingesting IPC files from untrusted sources, this could plausibly be exploited for denial of service. Inducing more targeted kinds of misbehavior (such as confidential data extraction from the running process) depends on memory allocation and multi-threaded IO temporal patterns that are unlikely to be easily controlled by an attacker.\n\nAdvice for users of Arrow C++:\n\n1. check whether you enable pre-buffering on the IPC file reader (using `RecordBatchFileReader::PreBufferMetadata`)\n\n2. if so, either disable pre-buffering (which may have adverse performance consequences), or switch to Arrow 23.0.1 which is not vulnerable", + "Severity": "HIGH", + "CweIDs": [ + "CWE-416" + ], + "VendorSeverity": { + "azure": 2, + "ghsa": 3, + "julia": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7 + }, + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H", + "V3Score": 5.3 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/02/17/4", + "https://access.redhat.com/security/cve/CVE-2026-25087", + "https://github.com/advisories/GHSA-rgxp-2hwp-jwgg", + "https://github.com/apache/arrow", + "https://github.com/apache/arrow/pull/48925", + "https://github.com/pypa/advisory-database/tree/main/vulns/pyarrow/PYSEC-2026-113.yaml", + "https://lists.apache.org/thread/mpm4ld1qony30tchfpjtk5b11tcyvmwh", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25087", + "https://www.cve.org/CVERecord?id=CVE-2026-25087" + ], + "PublishedDate": "2026-02-17T14:16:01.947Z", + "LastModifiedDate": "2026-06-17T10:24:05.973Z" + }, + { + "VulnerabilityID": "CVE-2025-66418", + "VendorIDs": [ + "GHSA-gm62-xv2j-4w53" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.5.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.5.0", + "UID": "1fe36bfbe9aa1cc5" + }, + "InstalledVersion": "2.5.0", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66418", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f3fd32f418021ee320d14a9ba23ecd983708a3bd57f838c4c3e04d5baff443c0", + "Title": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66418", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53", + "https://linux.oracle.com/cve/CVE-2025-66418.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66418", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://www.cve.org/CVERecord?id=CVE-2025-66418", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T16:15:51.053Z", + "LastModifiedDate": "2026-06-17T09:56:48.383Z" + }, + { + "VulnerabilityID": "CVE-2025-66471", + "VendorIDs": [ + "GHSA-2xpw-w6gg-jr37" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.5.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.5.0", + "UID": "1fe36bfbe9aa1cc5" + }, + "InstalledVersion": "2.5.0", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66471", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:55a9592003839076bc349bf0a02c2e2f71bfa456931607ce0aef8c51f68d5bd9", + "Title": "urllib3: urllib3 Streaming API improperly handles highly compressed data", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66471", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37", + "https://linux.oracle.com/cve/CVE-2025-66471.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66471", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-7927-2", + "https://ubuntu.com/security/notices/USN-7927-3", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://ubuntu.com/security/notices/USN-8344-2", + "https://ubuntu.com/security/notices/USN-8344-3", + "https://www.cve.org/CVERecord?id=CVE-2025-66471", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T17:16:04.4Z", + "LastModifiedDate": "2026-06-17T09:56:53.65Z" + }, + { + "VulnerabilityID": "CVE-2026-21441", + "VendorIDs": [ + "GHSA-38jv-5279-wg99" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.5.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.5.0", + "UID": "1fe36bfbe9aa1cc5" + }, + "InstalledVersion": "2.5.0", + "FixedVersion": "2.6.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-21441", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f24b83b603f6565dd328358c6c7a08d5bfbff7263026977b2a14f56db5355a2f", + "Title": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)", + "Description": "urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V3Score": 7.5, + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0981", + "https://access.redhat.com/errata/RHSA-2026:0990", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:1038", + "https://access.redhat.com/errata/RHSA-2026:1041", + "https://access.redhat.com/errata/RHSA-2026:1042", + "https://access.redhat.com/errata/RHSA-2026:1086", + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1088", + "https://access.redhat.com/errata/RHSA-2026:1089", + "https://access.redhat.com/errata/RHSA-2026:1166", + "https://access.redhat.com/errata/RHSA-2026:1168", + "https://access.redhat.com/errata/RHSA-2026:1176", + "https://access.redhat.com/errata/RHSA-2026:1224", + "https://access.redhat.com/errata/RHSA-2026:1226", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/errata/RHSA-2026:1240", + "https://access.redhat.com/errata/RHSA-2026:1241", + "https://access.redhat.com/errata/RHSA-2026:1254", + "https://access.redhat.com/errata/RHSA-2026:1485", + "https://access.redhat.com/errata/RHSA-2026:14877", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:1546", + "https://access.redhat.com/errata/RHSA-2026:1596", + "https://access.redhat.com/errata/RHSA-2026:1599", + "https://access.redhat.com/errata/RHSA-2026:1609", + "https://access.redhat.com/errata/RHSA-2026:1618", + "https://access.redhat.com/errata/RHSA-2026:1619", + "https://access.redhat.com/errata/RHSA-2026:1652", + "https://access.redhat.com/errata/RHSA-2026:1674", + "https://access.redhat.com/errata/RHSA-2026:1676", + "https://access.redhat.com/errata/RHSA-2026:1693", + "https://access.redhat.com/errata/RHSA-2026:1704", + "https://access.redhat.com/errata/RHSA-2026:1706", + "https://access.redhat.com/errata/RHSA-2026:1712", + "https://access.redhat.com/errata/RHSA-2026:1717", + "https://access.redhat.com/errata/RHSA-2026:1726", + "https://access.redhat.com/errata/RHSA-2026:1729", + "https://access.redhat.com/errata/RHSA-2026:1730", + "https://access.redhat.com/errata/RHSA-2026:1734", + "https://access.redhat.com/errata/RHSA-2026:1735", + "https://access.redhat.com/errata/RHSA-2026:1736", + "https://access.redhat.com/errata/RHSA-2026:17456", + "https://access.redhat.com/errata/RHSA-2026:17457", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17461", + "https://access.redhat.com/errata/RHSA-2026:17462", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:1791", + "https://access.redhat.com/errata/RHSA-2026:1792", + "https://access.redhat.com/errata/RHSA-2026:1793", + "https://access.redhat.com/errata/RHSA-2026:1794", + "https://access.redhat.com/errata/RHSA-2026:1803", + "https://access.redhat.com/errata/RHSA-2026:1805", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:1957", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2126", + "https://access.redhat.com/errata/RHSA-2026:2137", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2144", + "https://access.redhat.com/errata/RHSA-2026:2256", + "https://access.redhat.com/errata/RHSA-2026:2456", + "https://access.redhat.com/errata/RHSA-2026:2500", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:2563", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2717", + "https://access.redhat.com/errata/RHSA-2026:2718", + "https://access.redhat.com/errata/RHSA-2026:2723", + "https://access.redhat.com/errata/RHSA-2026:2728", + "https://access.redhat.com/errata/RHSA-2026:2760", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2764", + "https://access.redhat.com/errata/RHSA-2026:2765", + "https://access.redhat.com/errata/RHSA-2026:28043", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2911", + "https://access.redhat.com/errata/RHSA-2026:2919", + "https://access.redhat.com/errata/RHSA-2026:2924", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:2926", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:33154", + "https://access.redhat.com/errata/RHSA-2026:3406", + "https://access.redhat.com/errata/RHSA-2026:3444", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:44696", + "https://access.redhat.com/errata/RHSA-2026:51357", + "https://access.redhat.com/errata/RHSA-2026:5459", + "https://access.redhat.com/errata/RHSA-2026:6287", + "https://access.redhat.com/errata/RHSA-2026:6292", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8500", + "https://access.redhat.com/errata/RHSA-2026:8501", + "https://access.redhat.com/security/cve/CVE-2026-21441", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99", + "https://linux.oracle.com/cve/CVE-2026-21441.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-21441", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json", + "https://ubuntu.com/security/notices/USN-7955-1", + "https://ubuntu.com/security/notices/USN-7955-2", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2026-21441" + ], + "PublishedDate": "2026-01-07T22:15:44.04Z", + "LastModifiedDate": "2026-08-14T13:17:38.737Z" + }, + { + "VulnerabilityID": "CVE-2026-44431", + "VendorIDs": [ + "GHSA-qccp-gfcp-xxvc" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.5.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.5.0", + "UID": "1fe36bfbe9aa1cc5" + }, + "InstalledVersion": "2.5.0", + "FixedVersion": "2.7.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44431", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:4d7ee816f4ec60b155fcb8e23d368d0b86707667d12256af2525ff5c85eea5c8", + "Title": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers", + "Description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V3Score": 5.3, + "V40Score": 8.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:28158", + "https://access.redhat.com/errata/RHSA-2026:28159", + "https://access.redhat.com/security/cve/CVE-2026-44431", + "https://bugzilla.redhat.com/2477154", + "https://bugzilla.redhat.com/2477167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477154", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477167", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432", + "https://errata.almalinux.org/9/ALSA-2026-28159.html", + "https://errata.rockylinux.org/RLSA-2026:28158", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc", + "https://linux.oracle.com/cve/CVE-2026-44431.html", + "https://linux.oracle.com/errata/ELSA-2026-49927.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44431", + "https://ubuntu.com/security/notices/USN-8379-1", + "https://www.cve.org/CVERecord?id=CVE-2026-44431" + ], + "PublishedDate": "2026-05-13T16:16:57.15Z", + "LastModifiedDate": "2026-06-26T12:16:32.423Z" + }, + { + "VulnerabilityID": "CVE-2026-24049", + "VendorIDs": [ + "GHSA-8rrh-rw8j-w5fx" + ], + "PkgName": "wheel", + "PkgPath": "usr/local/lib/python3.12/site-packages/setuptools/_vendor/wheel-0.45.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/wheel@0.45.1", + "UID": "6fb8715934c98d27" + }, + "InstalledVersion": "0.45.1", + "FixedVersion": "0.46.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-24049", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:388d0bbde43c7261dce447ebf28fa21fd8882a8f437ead68e1b910357ead384c", + "Title": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking", + "Description": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22", + "CWE-732" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", + "V3Score": 5.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:1902", + "https://access.redhat.com/errata/RHSA-2026:1939", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:2090", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2675", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2694", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2710", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2823", + "https://access.redhat.com/errata/RHSA-2026:2865", + "https://access.redhat.com/errata/RHSA-2026:2866", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5119", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6555", + "https://access.redhat.com/errata/RHSA-2026:6562", + "https://access.redhat.com/errata/RHSA-2026:6565", + "https://access.redhat.com/errata/RHSA-2026:7250", + "https://access.redhat.com/security/cve/CVE-2026-24049", + "https://bugzilla.redhat.com/2431959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2431959", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24049", + "https://errata.almalinux.org/9/ALSA-2026-1939.html", + "https://errata.rockylinux.org/RLSA-2026:1939", + "https://github.com/pypa/wheel", + "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef", + "https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e", + "https://github.com/pypa/wheel/releases/tag/0.46.2", + "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx", + "https://linux.oracle.com/cve/CVE-2026-24049.html", + "https://linux.oracle.com/errata/ELSA-2026-2090.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-24049", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json", + "https://ubuntu.com/security/notices/USN-8221-1", + "https://www.cve.org/CVERecord?id=CVE-2026-24049" + ], + "PublishedDate": "2026-01-22T05:16:23.157Z", + "LastModifiedDate": "2026-08-12T12:17:55.967Z" + }, + { + "VulnerabilityID": "CVE-2026-24049", + "VendorIDs": [ + "GHSA-8rrh-rw8j-w5fx" + ], + "PkgName": "wheel", + "PkgPath": "usr/local/lib/python3.12/site-packages/wheel-0.45.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/wheel@0.45.1", + "UID": "36e27261436629ac" + }, + "InstalledVersion": "0.45.1", + "FixedVersion": "0.46.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cfd92e15532e56fa1ced4a03c69157105963900eac3cfe88a1f4359e582bf113", + "DiffID": "sha256:ba3647c1165ff50bc105dfac0bc532c277a113022f45886b0c2250a1f818b6c2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-24049", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:388d0bbde43c7261dce447ebf28fa21fd8882a8f437ead68e1b910357ead384c", + "Title": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking", + "Description": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22", + "CWE-732" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", + "V3Score": 5.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:1902", + "https://access.redhat.com/errata/RHSA-2026:1939", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:2090", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2675", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2694", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2710", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2823", + "https://access.redhat.com/errata/RHSA-2026:2865", + "https://access.redhat.com/errata/RHSA-2026:2866", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5119", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6555", + "https://access.redhat.com/errata/RHSA-2026:6562", + "https://access.redhat.com/errata/RHSA-2026:6565", + "https://access.redhat.com/errata/RHSA-2026:7250", + "https://access.redhat.com/security/cve/CVE-2026-24049", + "https://bugzilla.redhat.com/2431959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2431959", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24049", + "https://errata.almalinux.org/9/ALSA-2026-1939.html", + "https://errata.rockylinux.org/RLSA-2026:1939", + "https://github.com/pypa/wheel", + "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef", + "https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e", + "https://github.com/pypa/wheel/releases/tag/0.46.2", + "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx", + "https://linux.oracle.com/cve/CVE-2026-24049.html", + "https://linux.oracle.com/errata/ELSA-2026-2090.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-24049", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json", + "https://ubuntu.com/security/notices/USN-8221-1", + "https://www.cve.org/CVERecord?id=CVE-2026-24049" + ], + "PublishedDate": "2026-01-22T05:16:23.157Z", + "LastModifiedDate": "2026-08-12T12:17:55.967Z" + } + ], + "vulnerability_count": 9 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 9 + } +} diff --git a/bfx/htslib/trivy-scan-results.json b/bfx/htslib/trivy-scan-results.json new file mode 100644 index 00000000..e9e115cc --- /dev/null +++ b/bfx/htslib/trivy-scan-results.json @@ -0,0 +1,16 @@ +{ + "tool": "htslib", + "scan_timestamp": "2026-08-16T17:07:13Z", + "workflow_run_id": "31960542324", + "versions": { + "1.24": { + "image": "ghcr.io/bundlecore/products/bfx/htslib:1.24", + "vulnerabilities": [], + "vulnerability_count": 0 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/htstream/trivy-scan-results.json b/bfx/htstream/trivy-scan-results.json new file mode 100644 index 00000000..768d2e64 --- /dev/null +++ b/bfx/htstream/trivy-scan-results.json @@ -0,0 +1,16 @@ +{ + "tool": "htstream", + "scan_timestamp": "2026-08-16T17:07:17Z", + "workflow_run_id": "31960542324", + "versions": { + "1.4.1": { + "image": "ghcr.io/bundlecore/products/bfx/htstream:1.4.1", + "vulnerabilities": [], + "vulnerability_count": 0 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/humann/trivy-scan-results.json b/bfx/humann/trivy-scan-results.json new file mode 100644 index 00000000..04177219 --- /dev/null +++ b/bfx/humann/trivy-scan-results.json @@ -0,0 +1,17766 @@ +{ + "tool": "humann", + "scan_timestamp": "2026-08-16T17:07:21Z", + "workflow_run_id": "31960542324", + "versions": { + "3.9": { + "image": "ghcr.io/bundlecore/products/bfx/humann:3.9", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2025-6176", + "VendorIDs": [ + "GHSA-2qfp-q593-8484" + ], + "PkgName": "Brotli", + "PkgPath": "usr/local/lib/python3.12/site-packages/Brotli-1.1.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/brotli@1.1.0", + "UID": "a7d383a006e445a1" + }, + "InstalledVersion": "1.1.0", + "FixedVersion": "1.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-6176", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:64b45bea3db96a008ad8cf1cf610a27fca40d5fb67c71b5af1fbc105b93c2e8f", + "Title": "Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS", + "Description": "Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:2042", + "https://access.redhat.com/security/cve/CVE-2025-6176", + "https://bugzilla.redhat.com/2408762", + "https://bugzilla.redhat.com/show_bug.cgi?id=2408762", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6176", + "https://errata.almalinux.org/9/ALSA-2026-2042.html", + "https://errata.rockylinux.org/RLSA-2026:2042", + "https://github.com/google/brotli", + "https://github.com/google/brotli/commit/67d78bc41db1a0d03f2e763497748f2f69946627", + "https://github.com/google/brotli/issues/1327", + "https://github.com/google/brotli/issues/1375", + "https://github.com/google/brotli/pull/1234", + "https://github.com/google/brotli/releases/tag/v1.2.0", + "https://github.com/scrapy/scrapy/commit/14737e91edc513967f516fc839cc9c8a4f8d91da", + "https://github.com/scrapy/scrapy/pull/7134", + "https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0", + "https://linux.oracle.com/cve/CVE-2025-6176.html", + "https://linux.oracle.com/errata/ELSA-2026-2389.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-6176", + "https://www.cve.org/CVERecord?id=CVE-2025-6176" + ], + "PublishedDate": "2025-10-31T00:15:37.333Z", + "LastModifiedDate": "2026-06-17T10:01:19.72Z" + }, + { + "VulnerabilityID": "CVE-2025-43859", + "VendorIDs": [ + "GHSA-vqfr-h8mv-ghfj" + ], + "PkgName": "h11", + "PkgPath": "usr/local/lib/python3.12/site-packages/h11-0.14.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/h11@0.14.0", + "UID": "a8e385eacc0731b3" + }, + "InstalledVersion": "0.14.0", + "FixedVersion": "0.16.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-43859", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:4e9adafd37e7cb725104ecaa565717bc9e5318b6bfb7e1e08b8f6e73c5c0cf50", + "Title": "h11: h11 accepts some malformed Chunked-Encoding bodies", + "Description": "h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-444" + ], + "VendorSeverity": { + "ghsa": 4, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2025-43859", + "https://github.com/python-hyper/h11", + "https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed", + "https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj", + "https://nvd.nist.gov/vuln/detail/CVE-2025-43859", + "https://ubuntu.com/security/notices/USN-7503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-43859" + ], + "PublishedDate": "2025-04-24T19:15:47.06Z", + "LastModifiedDate": "2026-06-17T09:24:39.58Z" + }, + { + "VulnerabilityID": "CVE-2025-30167", + "VendorIDs": [ + "GHSA-33p9-3p43-82vq" + ], + "PkgName": "jupyter_core", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_core-5.7.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-core@5.7.2", + "UID": "abb9dc71f60bd5b8" + }, + "InstalledVersion": "5.7.2", + "FixedVersion": "5.8.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-30167", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:e1a2eb8e02c98254f53a2b7215295f93e4a22c709edf2acf8326e1e1bda8b599", + "Title": "Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability", + "Description": "Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users. Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected. Users should upgrade to Jupyter Core version 5.8.0 or later to receive a patch. Some other mitigations are available. As administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users; or as administrator, create the `%PROGRAMDATA%\\jupyter` directory with appropriately restrictive permissions; or as user or administrator, set the `%PROGRAMDATA%` environment variable to a directory with appropriately restrictive permissions (e.g. controlled by administrators _or_ the current user).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-427" + ], + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.3 + } + }, + "References": [ + "https://github.com/jupyter/jupyter_core", + "https://github.com/jupyter/jupyter_core/commit/5e8965600adda6b416692ce7e85ecb2bd814bd52", + "https://github.com/jupyter/jupyter_core/security/advisories/GHSA-33p9-3p43-82vq", + "https://nvd.nist.gov/vuln/detail/CVE-2025-30167" + ], + "PublishedDate": "2025-06-03T17:15:21.52Z", + "LastModifiedDate": "2026-06-17T09:08:17.083Z" + }, + { + "VulnerabilityID": "CVE-2026-44727", + "VendorIDs": [ + "GHSA-fcw5-x6j4-ccmp" + ], + "PkgName": "jupyter_server", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_server-2.14.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-server@2.14.1", + "UID": "2cf1353c68bbbeae" + }, + "InstalledVersion": "2.14.1", + "FixedVersion": "2.20.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44727", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:7e53bc455524fdebf12248bf05ef62b967e41fb0bf347fc95687ac179bbce42d", + "Title": "jupyter-server: Jupyter Server: Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers", + "Description": "Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE. This vulnerability is fixed in 2.20.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-79", + "CWE-1021" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 2, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H", + "V3Score": 5.4, + "V40Score": 9.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 5.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-44727", + "https://bugzilla.redhat.com/show_bug.cgi?id=2491516", + "https://github.com/advisories/GHSA-fcw5-x6j4-ccmp", + "https://github.com/jupyter-server/jupyter_server", + "https://github.com/jupyter-server/jupyter_server/commit/6cbee8d65e71abac851c4492fea987ad080580bd", + "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmp", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-366.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44727", + "https://pypi.org/project/jupyter-server", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44727.json", + "https://www.cve.org/CVERecord?id=CVE-2026-44727" + ], + "PublishedDate": "2026-06-22T21:16:24.26Z", + "LastModifiedDate": "2026-07-22T12:18:06.24Z" + }, + { + "VulnerabilityID": "CVE-2026-35397", + "VendorIDs": [ + "GHSA-5789-5fc7-67v3" + ], + "PkgName": "jupyter_server", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_server-2.14.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-server@2.14.1", + "UID": "2cf1353c68bbbeae" + }, + "InstalledVersion": "2.14.1", + "FixedVersion": "2.18.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-35397", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f17f4b9a316ddd770f029a11f1c930565f29ccf054578477459a8d6184334e87", + "Title": "jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability", + "Description": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named \"test\", the API permits access to a sibling directory named \"testtest\" through a crafted request to the /api/contents endpoint using encoded path components. An attacker can read, write, and delete files in affected sibling directories. Multi-tenant deployments using predictable naming schemes are particularly at risk, as a user with a directory named \"user1\" could access directories for user10 through user19 and beyond. A user who can choose a single-character folder name could gain access to a significant number of sibling directories. \n\nVersion 2.18.0 contains a fix. As a workaround, ensure folder names do not share a common prefix with any sibling directory.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N", + "V3Score": 7.1, + "V40Score": 7.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-35397", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466858", + "https://github.com/jupyter-server/jupyter_server", + "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-68.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-35397", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35397.json", + "https://www.cve.org/CVERecord?id=CVE-2026-35397" + ], + "PublishedDate": "2026-05-05T20:16:38.223Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-40110", + "VendorIDs": [ + "GHSA-24qx-w28j-9m6p" + ], + "PkgName": "jupyter_server", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_server-2.14.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-server@2.14.1", + "UID": "2cf1353c68bbbeae" + }, + "InstalledVersion": "2.14.1", + "FixedVersion": "2.18.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40110", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:663ba692f03d660c5a8123d5ce3e00b179533f22139d478de5c617e2cf7bac47", + "Title": "jupyter-server: Jupyter Server: Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation", + "Description": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-777", + "CWE-625" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L", + "V40Score": 7.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-40110", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466912", + "https://github.com/jupyter-server/jupyter_server", + "https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea", + "https://github.com/jupyter-server/jupyter_server/commit/49b34392feaa97735b3b777e3baf8f22f2a14ed8", + "https://github.com/jupyter-server/jupyter_server/pull/603", + "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-2187.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40110", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40110.json", + "https://www.cve.org/CVERecord?id=CVE-2026-40110" + ], + "PublishedDate": "2026-05-05T22:16:00.663Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-40934", + "VendorIDs": [ + "GHSA-5mrq-x3x5-8v8f" + ], + "PkgName": "jupyter_server", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_server-2.14.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-server@2.14.1", + "UID": "2cf1353c68bbbeae" + }, + "InstalledVersion": "2.14.1", + "FixedVersion": "2.18.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40934", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b4b77b5ca7776428bf9400fea4b5770398a3528c88fda6e4df2c19041ba96f2a", + "Title": "jupyter-server: Jupyter Server: Authentication bypass due to unrotated cookie secret", + "Description": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-613" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 2, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", + "V3Score": 6.8, + "V40Score": 7.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-40934", + "https://github.com/jupyter-server/jupyter_server", + "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-69.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40934", + "https://www.cve.org/CVERecord?id=CVE-2026-40934" + ], + "PublishedDate": "2026-05-05T22:16:00.82Z", + "LastModifiedDate": "2026-07-25T11:10:00.1Z" + }, + { + "VulnerabilityID": "CVE-2024-43805", + "VendorIDs": [ + "GHSA-9q39-rmj3-p4r2" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.2.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.2.2", + "UID": "6bba20879e1e7f1d" + }, + "InstalledVersion": "4.2.2", + "FixedVersion": "3.6.8, 4.2.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-43805", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:4c19736e3d25dd7609b73bc94da2b7904a7615ed62bcdb09127009d3d70bd9f5", + "Title": "jupyterlab is an extensible environment for interactive and reproducib ...", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has access to as well as perform arbitrary requests acting as the attacked user. JupyterLab v3.6.8, v4.2.5 and Jupyter Notebook v7.2.2 have been patched to resolve this issue. Users are advised to upgrade. There is no workaround for the underlying DOM Clobbering susceptibility. However, select plugins can be disabled on deployments which cannot update in a timely fashion to minimise the risk. These are: 1. `@jupyterlab/mathjax-extension:plugin` - users will loose ability to preview mathematical equations. 2. `@jupyterlab/markdownviewer-extension:plugin` - users will loose ability to open Markdown previews. 3. `@jupyterlab/mathjax2-extension:plugin` (if installed with optional `jupyterlab-mathjax2` package) - an older version of the mathjax plugin for JupyterLab 4.x. To disable these extensions run: ```jupyter labextension disable @jupyterlab/markdownviewer-extension:plugin && jupyter labextension disable @jupyterlab/mathjax-extension:plugin && jupyter labextension disable @jupyterlab/mathjax2-extension:plugin ``` in bash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 2, + "ghsa": 3, + "nvd": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 6.1 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N", + "V3Score": 7.6, + "V40Score": 8.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 6.1 + } + }, + "References": [ + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/commit/06ad9de836f155add7d3d651ef936cc4c5ea8093", + "https://github.com/jupyterlab/jupyterlab/commit/88e24baac551196f9cb3de16bd060a7ab1597674", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-9q39-rmj3-p4r2", + "https://nvd.nist.gov/vuln/detail/CVE-2024-43805" + ], + "PublishedDate": "2024-08-28T20:15:07.963Z", + "LastModifiedDate": "2026-06-17T07:51:44.833Z" + }, + { + "VulnerabilityID": "CVE-2026-40171", + "VendorIDs": [ + "GHSA-rch3-82jr-f9w9" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.2.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.2.2", + "UID": "6bba20879e1e7f1d" + }, + "InstalledVersion": "4.2.2", + "FixedVersion": "4.5.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40171", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:8998a2269fddcb301f46753b17bac5bddfe8ffb2e5f94934f35b288912338849", + "Title": "Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting", + "Description": "In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.\n\nAn attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's authentication token and complete takeover of the Jupyter session through the REST API, including reading files, creating or modifying files, accessing kernels to execute arbitrary code, and creating terminals for shell access. This issue has been fixed in Notebook 7.5.6, JupyterLab 4.5.7, @jupyter-notebook/help-extension 7.5.6, and @jupyterlab/help-extension 4.5.7. As a workaround, disable the affected help extensions or set allowCommandLinker to false in the sanitizer configuration.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.4 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-40171", + "https://github.com/jupyter/notebook", + "https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9", + "https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-output-and-files", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40171", + "https://www.cve.org/CVERecord?id=CVE-2026-40171" + ], + "PublishedDate": "2026-05-06T20:16:31.857Z", + "LastModifiedDate": "2026-06-17T10:44:48.747Z" + }, + { + "VulnerabilityID": "CVE-2026-42266", + "VendorIDs": [ + "GHSA-37w4-hwhx-4rc4" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.2.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.2.2", + "UID": "6bba20879e1e7f1d" + }, + "InstalledVersion": "4.2.2", + "FixedVersion": "4.5.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42266", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f3575314fc12e23cdb6ec046e51578ad138f032ba7aa68768e83660e44c49e3b", + "Title": "jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list", + "Description": "JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-88", + "CWE-602" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-42266", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477072", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyterlab/PYSEC-2026-164.yaml", + "https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html", + "https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42266", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42266.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42266" + ], + "PublishedDate": "2026-05-13T16:16:47.017Z", + "LastModifiedDate": "2026-07-22T12:17:54.223Z" + }, + { + "VulnerabilityID": "CVE-2026-42557", + "VendorIDs": [ + "GHSA-mqcg-5x36-vfcg" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.2.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.2.2", + "UID": "6bba20879e1e7f1d" + }, + "InstalledVersion": "4.2.2", + "FixedVersion": "4.5.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42557", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9548229e8e3b7383da500c251dbf0032a9afd3b5db52190681e4fefec1d94f56", + "Title": "jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.7, + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 9.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-42557", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477086", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg", + "https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-files", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42557", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42557.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42557" + ], + "PublishedDate": "2026-05-13T16:16:48.167Z", + "LastModifiedDate": "2026-07-22T12:17:56.103Z" + }, + { + "VulnerabilityID": "CVE-2026-73415", + "VendorIDs": [ + "GHSA-gx64-gj6p-pc4c" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.2.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.2.2", + "UID": "6bba20879e1e7f1d" + }, + "InstalledVersion": "4.2.2", + "FixedVersion": "4.6.2, 4.5.10", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-73415", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:dfe439375029195b8df27a5561edad1459983f02131003cf2c56abeccb31b980", + "Title": "jupyterlab: JupyterLab: Arbitrary code execution via malicious image in image viewer", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early, allowing the image to retain an executable same-origin context when it is opened through the image viewer and then opened in a new browser tab. The resulting cross-site scripting can be used to execute arbitrary code on the JupyterLab server. This issue is fixed in versions 4.5.10 and 4.6.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N", + "V40Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-73415", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/commit/9365f020baec5221deaf11535ed554c06637c999", + "https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c", + "https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432", + "https://github.com/jupyterlab/jupyterlab/pull/19184", + "https://github.com/jupyterlab/jupyterlab/pull/19185", + "https://github.com/jupyterlab/jupyterlab/pull/19186", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.7.0a1", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c", + "https://nvd.nist.gov/vuln/detail/CVE-2026-73415", + "https://www.cve.org/CVERecord?id=CVE-2026-73415" + ], + "PublishedDate": "2026-08-12T20:17:56.66Z", + "LastModifiedDate": "2026-08-12T21:17:40.77Z" + }, + { + "VulnerabilityID": "CVE-2026-73417", + "VendorIDs": [ + "GHSA-pppj-hq3g-57pj" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.2.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.2.2", + "UID": "6bba20879e1e7f1d" + }, + "InstalledVersion": "4.2.2", + "FixedVersion": "4.6.2, 4.5.10", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-73417", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c1d9233d6e4225f95a42289bdc448a72b0355b6187d076f3e9c5ff55e2596943", + "Title": "jupyterlab: JupyterLab: Cross-site scripting (XSS) allows arbitrary code execution", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an overrides.json file using the Import button in the Settings Editor. In packages/notebook-extension/schema/tracker.json and packages/notebook-extension/src/index.ts, the sideBySideLeftMarginOverride and sideBySideRightMarginOverride settings are not properly validated before being inserted into style content, allowing a crafted settings file to contain instructions that execute as code instead of only changing display preferences. A user can import the malicious file, or an attacker with access to a shared settings location can plant an overrides.json that is applied automatically. The embedded code runs with the affected user's access and can read or modify notebooks and files and run code through the notebook server, including on a connected kernel. This issue is fixed in versions 4.5.10 and 4.6.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79", + "CWE-116" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:L", + "V40Score": 8.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L", + "V3Score": 8.3 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-73417", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/commit/9365f020baec5221deaf11535ed554c06637c999", + "https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c", + "https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432", + "https://github.com/jupyterlab/jupyterlab/pull/19184", + "https://github.com/jupyterlab/jupyterlab/pull/19185", + "https://github.com/jupyterlab/jupyterlab/pull/19186", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.7.0a1", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-73417", + "https://www.cve.org/CVERecord?id=CVE-2026-73417" + ], + "PublishedDate": "2026-08-13T22:17:26.133Z", + "LastModifiedDate": "2026-08-14T17:20:32.837Z" + }, + { + "VulnerabilityID": "CVE-2026-33079", + "VendorIDs": [ + "GHSA-8mp2-v27r-99xp" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.0.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.0.2", + "UID": "ff123e4b5870759" + }, + "InstalledVersion": "3.0.2", + "FixedVersion": "3.2.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33079", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:0e0fe13dbe8d55d2975db8d6ff20691dc181168855c63e8c93e7c3557b617512", + "Title": "mistune: Mistune: Regular Expression Denial of Service (ReDoS) via crafted Markdown input", + "Description": "In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles contains overlapping alternatives that can trigger catastrophic backtracking. In both the double-quoted and single-quoted branches, a backslash followed by punctuation can be matched either as an escaped punctuation sequence or as two ordinary characters, creating an ambiguous pattern inside a repeated group. If an attacker supplies Markdown containing repeated ! sequences with no closing quote, the regex engine explores an exponential number of backtracking paths. This is reachable through normal Markdown parsing of inline links and block link reference definitions. A small crafted input can therefore cause significant CPU consumption and make applications using Mistune unresponsive.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-33079", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467298", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/blob/df23edd60b43b639d2e6760ef9dd3d618aa11c21/src/mistune/helpers.py#L20-L25", + "https://github.com/lepture/mistune/security/advisories/GHSA-8mp2-v27r-99xp", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33079", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33079.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33079" + ], + "PublishedDate": "2026-05-06T18:16:03.097Z", + "LastModifiedDate": "2026-07-22T12:17:35.443Z" + }, + { + "VulnerabilityID": "CVE-2026-49851", + "VendorIDs": [ + "GHSA-qcq2-496w-v96p" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.0.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.0.2", + "UID": "ff123e4b5870759" + }, + "InstalledVersion": "3.0.2", + "FixedVersion": "3.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49851", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:0ff62255b286c89c0bbf08048bf8f7129b2e086efd61ddca8eebd526aeae22a3", + "Title": "Mistune: Mistune: Denial of Service via crafted Markdown input", + "Description": "Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repeatedly scans the input using a regex search inside a loop. Each iteration re-scans a large portion of the remaining string, resulting in quadratic-time behavior. An attacker-controlled Markdown input can therefore trigger excessive CPU usage with a very small payload. This vulnerability is fixed in 3.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-407", + "CWE-770", + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-49851", + "https://bugzilla.redhat.com/show_bug.cgi?id=2492304", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p", + "https://nvd.nist.gov/vuln/detail/CVE-2026-49851", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49851.json", + "https://www.cve.org/CVERecord?id=CVE-2026-49851" + ], + "PublishedDate": "2026-06-24T18:17:18.937Z", + "LastModifiedDate": "2026-07-15T02:22:36.243Z" + }, + { + "VulnerabilityID": "CVE-2026-59922", + "VendorIDs": [ + "GHSA-c8j7-8cv4-2xmq" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.0.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.0.2", + "UID": "ff123e4b5870759" + }, + "InstalledVersion": "3.0.2", + "FixedVersion": "3.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59922", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:fa1756a55967936da50432f4c8078b16bbf73ca4366ebe1fd9f04a3ff203c575", + "Title": "mistune: Mistune: Denial of Service via crafted input", + "Description": "Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start position, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407", + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59922", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7", + "https://github.com/lepture/mistune/releases/tag/v3.3.0", + "https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq", + "https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2210.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59922", + "https://www.cve.org/CVERecord?id=CVE-2026-59922" + ], + "PublishedDate": "2026-07-08T17:17:27.77Z", + "LastModifiedDate": "2026-07-09T19:36:00.01Z" + }, + { + "VulnerabilityID": "CVE-2026-59925", + "VendorIDs": [ + "GHSA-4j32-57v6-6g45" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.0.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.0.2", + "UID": "ff123e4b5870759" + }, + "InstalledVersion": "3.0.2", + "FixedVersion": "3.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59925", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:6afb4e362b3a29344aefef169888ff864de4f11478f454e2cc89b9eea40dc0b0", + "Title": "mistune: Mistune: Denial of Service via crafted Markdown input", + "Description": "Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential opening run, allowing denial of service in default Mistune parsing. This issue is fixed in version 3.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407", + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59925", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f", + "https://github.com/lepture/mistune/releases/tag/v3.3.0", + "https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45", + "https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2213.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59925", + "https://www.cve.org/CVERecord?id=CVE-2026-59925" + ], + "PublishedDate": "2026-07-08T17:17:28.183Z", + "LastModifiedDate": "2026-07-09T19:39:58.87Z" + }, + { + "VulnerabilityID": "CVE-2026-59928", + "VendorIDs": [ + "GHSA-ffq3-xpv3-j92q" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.0.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.0.2", + "UID": "ff123e4b5870759" + }, + "InstalledVersion": "3.0.2", + "FixedVersion": "3.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59928", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:23f54afe7691b4efaf881432d7e16f8a82021758a057c7068af4fd6528e860e6", + "Title": "mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitions", + "Description": "Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407", + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59928", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69", + "https://github.com/lepture/mistune/releases/tag/v3.3.0", + "https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q", + "https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2216.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59928", + "https://www.cve.org/CVERecord?id=CVE-2026-59928" + ], + "PublishedDate": "2026-07-08T17:17:28.6Z", + "LastModifiedDate": "2026-07-09T19:29:34.207Z" + }, + { + "VulnerabilityID": "CVE-2025-53000", + "VendorIDs": [ + "GHSA-xm59-rqc7-hhvf" + ], + "PkgName": "nbconvert", + "PkgPath": "usr/local/lib/python3.12/site-packages/nbconvert-7.16.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/nbconvert@7.16.4", + "UID": "b4b72c7cc7aa76d9" + }, + "InstalledVersion": "7.16.4", + "FixedVersion": "7.17.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-53000", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:1628a7bc7d9245a99bff1eacab0c3622c705045271b82fe2510a1e1c8d17672d", + "Title": "nbconvert: nbconvert: Arbitrary code execution via malicious SVG to PDF conversion on Windows", + "Description": "The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions of nbconvert up to and including 7.16.6 on Windows have a vulnerability in which converting a notebook containing SVG output to a PDF results in unauthorized code execution. Specifically, a third party can create a `inkscape.bat` file that defines a Windows batch script, capable of arbitrary code execution. When a user runs `jupyter nbconvert --to pdf` on a notebook containing SVG output to a PDF on a Windows platform from this directory, the `inkscape.bat` file is run unexpectedly. This issue has been patched in version 7.17.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-427" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2025-53000", + "https://github.com/jupyter/nbconvert", + "https://github.com/jupyter/nbconvert/blob/4f61702f5c7524d8a3c4ac0d5fc33a6ac2fa36a7/nbconvert/preprocessors/svg2pdf.py#L104", + "https://github.com/jupyter/nbconvert/commit/c9ac1d1040459ed1ff9eb34e9918ce5a87cf9d71", + "https://github.com/jupyter/nbconvert/issues/2258", + "https://github.com/jupyter/nbconvert/releases/tag/v7.17.0", + "https://github.com/jupyter/nbconvert/security/advisories/GHSA-xm59-rqc7-hhvf", + "https://nvd.nist.gov/vuln/detail/CVE-2025-53000", + "https://www.cve.org/CVERecord?id=CVE-2025-53000", + "https://www.imperva.com/blog/code-execution-in-jupyter-notebook-exports" + ], + "PublishedDate": "2025-12-17T21:16:14.473Z", + "LastModifiedDate": "2026-06-17T09:37:27.17Z" + }, + { + "VulnerabilityID": "CVE-2024-43805", + "VendorIDs": [ + "GHSA-9q39-rmj3-p4r2" + ], + "PkgName": "notebook", + "PkgPath": "usr/local/lib/python3.12/site-packages/notebook-7.2.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/notebook@7.2.1", + "UID": "ad829526d665d674" + }, + "InstalledVersion": "7.2.1", + "FixedVersion": "7.2.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-43805", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:4c19736e3d25dd7609b73bc94da2b7904a7615ed62bcdb09127009d3d70bd9f5", + "Title": "jupyterlab is an extensible environment for interactive and reproducib ...", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has access to as well as perform arbitrary requests acting as the attacked user. JupyterLab v3.6.8, v4.2.5 and Jupyter Notebook v7.2.2 have been patched to resolve this issue. Users are advised to upgrade. There is no workaround for the underlying DOM Clobbering susceptibility. However, select plugins can be disabled on deployments which cannot update in a timely fashion to minimise the risk. These are: 1. `@jupyterlab/mathjax-extension:plugin` - users will loose ability to preview mathematical equations. 2. `@jupyterlab/markdownviewer-extension:plugin` - users will loose ability to open Markdown previews. 3. `@jupyterlab/mathjax2-extension:plugin` (if installed with optional `jupyterlab-mathjax2` package) - an older version of the mathjax plugin for JupyterLab 4.x. To disable these extensions run: ```jupyter labextension disable @jupyterlab/markdownviewer-extension:plugin && jupyter labextension disable @jupyterlab/mathjax-extension:plugin && jupyter labextension disable @jupyterlab/mathjax2-extension:plugin ``` in bash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 2, + "ghsa": 3, + "nvd": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 6.1 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N", + "V3Score": 7.6, + "V40Score": 8.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 6.1 + } + }, + "References": [ + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/commit/06ad9de836f155add7d3d651ef936cc4c5ea8093", + "https://github.com/jupyterlab/jupyterlab/commit/88e24baac551196f9cb3de16bd060a7ab1597674", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-9q39-rmj3-p4r2", + "https://nvd.nist.gov/vuln/detail/CVE-2024-43805" + ], + "PublishedDate": "2024-08-28T20:15:07.963Z", + "LastModifiedDate": "2026-06-17T07:51:44.833Z" + }, + { + "VulnerabilityID": "CVE-2026-40171", + "VendorIDs": [ + "GHSA-rch3-82jr-f9w9" + ], + "PkgName": "notebook", + "PkgPath": "usr/local/lib/python3.12/site-packages/notebook-7.2.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/notebook@7.2.1", + "UID": "ad829526d665d674" + }, + "InstalledVersion": "7.2.1", + "FixedVersion": "7.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40171", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:8998a2269fddcb301f46753b17bac5bddfe8ffb2e5f94934f35b288912338849", + "Title": "Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting", + "Description": "In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.\n\nAn attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's authentication token and complete takeover of the Jupyter session through the REST API, including reading files, creating or modifying files, accessing kernels to execute arbitrary code, and creating terminals for shell access. This issue has been fixed in Notebook 7.5.6, JupyterLab 4.5.7, @jupyter-notebook/help-extension 7.5.6, and @jupyterlab/help-extension 4.5.7. As a workaround, disable the affected help extensions or set allowCommandLinker to false in the sanitizer configuration.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.4 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-40171", + "https://github.com/jupyter/notebook", + "https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9", + "https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-output-and-files", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40171", + "https://www.cve.org/CVERecord?id=CVE-2026-40171" + ], + "PublishedDate": "2026-05-06T20:16:31.857Z", + "LastModifiedDate": "2026-06-17T10:44:48.747Z" + }, + { + "VulnerabilityID": "CVE-2026-42557", + "VendorIDs": [ + "GHSA-mqcg-5x36-vfcg" + ], + "PkgName": "notebook", + "PkgPath": "usr/local/lib/python3.12/site-packages/notebook-7.2.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/notebook@7.2.1", + "UID": "ad829526d665d674" + }, + "InstalledVersion": "7.2.1", + "FixedVersion": "7.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42557", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9548229e8e3b7383da500c251dbf0032a9afd3b5db52190681e4fefec1d94f56", + "Title": "jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.7, + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 9.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-42557", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477086", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg", + "https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-files", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42557", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42557.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42557" + ], + "PublishedDate": "2026-05-13T16:16:48.167Z", + "LastModifiedDate": "2026-07-22T12:17:56.103Z" + }, + { + "VulnerabilityID": "CVE-2026-25990", + "VendorIDs": [ + "GHSA-cfh3-3jmp-rvhc" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25990", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:7e1f3181e1f9ed6fb62cd732c6a7dd2ef22023370abd2a876bc32adb01e25492", + "Title": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image", + "Description": "Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/02/12/1", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:14873", + "https://access.redhat.com/errata/RHSA-2026:14874", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:28385", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:4128", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6308", + "https://access.redhat.com/errata/RHSA-2026:6309", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/security/cve/CVE-2026-25990", + "https://bugzilla.redhat.com/show_bug.cgi?id=2439170", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199", + "https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa", + "https://github.com/python-pillow/Pillow/pull/9427", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25990", + "https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json", + "https://ubuntu.com/security/notices/USN-8047-1", + "https://www.cve.org/CVERecord?id=CVE-2026-25990" + ], + "PublishedDate": "2026-02-11T21:16:20.67Z", + "LastModifiedDate": "2026-08-12T12:18:09.957Z" + }, + { + "VulnerabilityID": "CVE-2026-40192", + "VendorIDs": [ + "GHSA-whj4-6x5x-4v2j" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40192", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b9be70877df10683adf8ee5362a2347eed2bb2664a12792a8238d99726d531a9", + "Title": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing", + "Description": "Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770", + "CWE-409" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:16008", + "https://access.redhat.com/errata/RHSA-2026:16009", + "https://access.redhat.com/errata/RHSA-2026:16030", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:17609", + "https://access.redhat.com/errata/RHSA-2026:17611", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22629", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24866", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:34366", + "https://access.redhat.com/errata/RHSA-2026:34368", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/security/cve/CVE-2026-40192", + "https://bugzilla.redhat.com/show_bug.cgi?id=2458856", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628", + "https://github.com/python-pillow/Pillow/pull/9521", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40192", + "https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json", + "https://ubuntu.com/security/notices/USN-8211-1", + "https://www.cve.org/CVERecord?id=CVE-2026-40192" + ], + "PublishedDate": "2026-04-15T23:16:10.053Z", + "LastModifiedDate": "2026-08-12T12:19:09.49Z" + }, + { + "VulnerabilityID": "CVE-2026-42311", + "VendorIDs": [ + "GHSA-pwv6-vv43-88gr" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42311", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:0dc4dc08f99c8d3b5023c6e5f178b25d39000e8900acfa1e452a5555d49ef085", + "Title": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing", + "Description": "Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42311", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea", + "https://github.com/python-pillow/Pillow/pull/9520", + "https://github.com/python-pillow/Pillow/releases/tag/12.2.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42311", + "https://ubuntu.com/security/notices/USN-8399-1", + "https://www.cve.org/CVERecord?id=CVE-2026-42311" + ], + "PublishedDate": "2026-05-09T06:16:10.43Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-54058", + "VendorIDs": [ + "GHSA-62p4-gmf7-7g93" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54058", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:43ef2624a6b2632ad28e8b4c9e7327db2b6ca9b20e6139f4d7e46b7acb8eab46", + "Title": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-54058", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d", + "https://github.com/python-pillow/Pillow/pull/9719", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93", + "https://linux.oracle.com/cve/CVE-2026-54058.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54058", + "https://www.cve.org/CVERecord?id=CVE-2026-54058" + ], + "PublishedDate": "2026-07-14T17:17:03.433Z", + "LastModifiedDate": "2026-08-06T15:46:05.867Z" + }, + { + "VulnerabilityID": "CVE-2026-54059", + "VendorIDs": [ + "GHSA-8v84-f9pq-wr9x" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54059", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f0190d9dd2b13f880da14c4d8d1ca858f315ecddf6447db59fc463735d351209", + "Title": "python-pillow: Pillow: Denial of Service via crafted PCF font data", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54059", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2253.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x", + "https://linux.oracle.com/cve/CVE-2026-54059.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54059", + "https://www.cve.org/CVERecord?id=CVE-2026-54059" + ], + "PublishedDate": "2026-07-06T19:17:08.127Z", + "LastModifiedDate": "2026-07-07T18:58:26.73Z" + }, + { + "VulnerabilityID": "CVE-2026-54060", + "VendorIDs": [ + "GHSA-5x94-69rx-g8h2" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54060", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:0572ee7621bc9101697ee783beda77ad6352c628ad58cb8a86a6c570a5d5d7f5", + "Title": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54060", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2", + "https://linux.oracle.com/cve/CVE-2026-54060.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54060", + "https://www.cve.org/CVERecord?id=CVE-2026-54060" + ], + "PublishedDate": "2026-07-06T19:17:08.27Z", + "LastModifiedDate": "2026-07-07T18:58:45.827Z" + }, + { + "VulnerabilityID": "CVE-2026-55379", + "VendorIDs": [ + "GHSA-45hq-cxwh-f6vc" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55379", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a4b0473c1c91533943a4b2a985d65c461cbdafc8e2d156b7734fcf61ade2fc60", + "Title": "python-pillow: Pillow: Denial of Service via crafted BDF font file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55379", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2255.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc", + "https://linux.oracle.com/cve/CVE-2026-55379.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55379", + "https://www.cve.org/CVERecord?id=CVE-2026-55379" + ], + "PublishedDate": "2026-07-06T19:17:08.577Z", + "LastModifiedDate": "2026-07-07T18:59:01.817Z" + }, + { + "VulnerabilityID": "CVE-2026-55380", + "VendorIDs": [ + "GHSA-phj9-mv4w-65pm" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55380", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c3c58bdf487ef4f543860e9f96645b56a9bfdeae6e956879b32c9da5a4361e5b", + "Title": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55380", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2256.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm", + "https://linux.oracle.com/cve/CVE-2026-55380.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55380", + "https://www.cve.org/CVERecord?id=CVE-2026-55380" + ], + "PublishedDate": "2026-07-06T19:17:08.703Z", + "LastModifiedDate": "2026-07-07T18:58:54.647Z" + }, + { + "VulnerabilityID": "CVE-2026-59197", + "VendorIDs": [ + "GHSA-xj96-63gp-2gmr" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59197", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3715c40a83324d0cd5d569fff91227d94a1d0ab4667e81b05f868870a213876e", + "Title": "Pillow: Pillow: Native heap out-of-bounds write", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-59197", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1", + "https://github.com/python-pillow/Pillow/pull/9695", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr", + "https://linux.oracle.com/cve/CVE-2026-59197.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59197", + "https://www.cve.org/CVERecord?id=CVE-2026-59197" + ], + "PublishedDate": "2026-07-14T17:17:14.487Z", + "LastModifiedDate": "2026-07-21T19:17:11.907Z" + }, + { + "VulnerabilityID": "CVE-2026-59199", + "VendorIDs": [ + "GHSA-6r8x-57c9-28j4" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59199", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a74f9c0f4d4e2130004738004640cf90d50c62393361ce586751d75c87dc6d3e", + "Title": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59199", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3451.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b", + "https://github.com/python-pillow/Pillow/pull/9703", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59199", + "https://www.cve.org/CVERecord?id=CVE-2026-59199" + ], + "PublishedDate": "2026-07-14T16:17:01.937Z", + "LastModifiedDate": "2026-07-15T16:16:49.487Z" + }, + { + "VulnerabilityID": "CVE-2026-59200", + "VendorIDs": [ + "GHSA-jjj6-mw9f-p565" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59200", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c89725b9e50d4bd31619c85754cc40462a4b7c9eccc3a85ba61b4e4d6c5fd398", + "Title": "Pillow: Pillow: Denial of service via crafted PDF stream", + "Description": "Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59200", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09", + "https://github.com/python-pillow/Pillow/pull/9718", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59200", + "https://www.cve.org/CVERecord?id=CVE-2026-59200" + ], + "PublishedDate": "2026-07-14T17:17:14.62Z", + "LastModifiedDate": "2026-07-21T15:52:40.107Z" + }, + { + "VulnerabilityID": "CVE-2026-59204", + "VendorIDs": [ + "GHSA-vjc4-5qp5-m44j" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59204", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3b7c8d1cf6a7b47090957bf9f29b797b4813b86b49fdaaad99bc8a0b58bef26b", + "Title": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image", + "Description": "Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59204", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca", + "https://github.com/python-pillow/Pillow/pull/9704", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59204", + "https://www.cve.org/CVERecord?id=CVE-2026-59204" + ], + "PublishedDate": "2026-07-14T16:17:02.227Z", + "LastModifiedDate": "2026-07-21T19:17:12.02Z" + }, + { + "VulnerabilityID": "CVE-2026-59205", + "VendorIDs": [ + "GHSA-9hw9-ch79-4vh6" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-10.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.3.0", + "UID": "e23dc911336914c4" + }, + "InstalledVersion": "10.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59205", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:99987e0b8a8f87c9a84c30d07d42999322a9cbd8f16e4c96032b40fc73c7ed15", + "Title": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59205", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3453.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721", + "https://github.com/python-pillow/Pillow/pull/9715", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59205", + "https://www.cve.org/CVERecord?id=CVE-2026-59205" + ], + "PublishedDate": "2026-07-14T16:17:02.37Z", + "LastModifiedDate": "2026-07-14T20:09:27.77Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgName": "setuptools", + "PkgPath": "usr/local/lib/python3.12/site-packages/setuptools-70.0.0-py3.12.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@70.0.0", + "UID": "771144fe6fb30d6d" + }, + "InstalledVersion": "70.0.0", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3ebbb552f84072f20d2ca125ee67b27f968548d28ab39d3903255c4ccd456d94", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:13578", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/9/ALSA-2025-13578.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + }, + { + "VulnerabilityID": "CVE-2026-49476", + "VendorIDs": [ + "GHSA-2wc2-fm75-p42x" + ], + "PkgName": "soupsieve", + "PkgPath": "usr/local/lib/python3.12/site-packages/soupsieve-2.5.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/soupsieve@2.5", + "UID": "2f028d5af3fcd903" + }, + "InstalledVersion": "2.5", + "FixedVersion": "2.8.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49476", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:21db6f05529009fe98273cbfb73af9ea5b79bc7b244fe95072b2aaf39cd5b5c4", + "Title": "python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string", + "Description": "Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-49476", + "https://github.com/facelessuser/soupsieve", + "https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39", + "https://github.com/facelessuser/soupsieve/releases/tag/2.8.4", + "https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x", + "https://nvd.nist.gov/vuln/detail/CVE-2026-49476", + "https://www.cve.org/CVERecord?id=CVE-2026-49476" + ], + "PublishedDate": "2026-07-14T21:17:01.877Z", + "LastModifiedDate": "2026-07-28T15:48:11.78Z" + }, + { + "VulnerabilityID": "CVE-2026-49477", + "VendorIDs": [ + "GHSA-836r-79rf-4m37" + ], + "PkgName": "soupsieve", + "PkgPath": "usr/local/lib/python3.12/site-packages/soupsieve-2.5.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/soupsieve@2.5", + "UID": "2f028d5af3fcd903" + }, + "InstalledVersion": "2.5", + "FixedVersion": "2.8.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49477", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:cf81c6e778a85215853c224e740694f284fd180741bf26c12cb8504853a90c64", + "Title": "soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings", + "Description": "Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-1333" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-49477", + "https://github.com/facelessuser/soupsieve", + "https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3", + "https://github.com/facelessuser/soupsieve/releases/tag/2.8.4", + "https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37", + "https://nvd.nist.gov/vuln/detail/CVE-2026-49477", + "https://www.cve.org/CVERecord?id=CVE-2026-49477" + ], + "PublishedDate": "2026-07-14T21:17:02.007Z", + "LastModifiedDate": "2026-07-28T15:48:00.76Z" + }, + { + "VulnerabilityID": "CVE-2024-52804", + "VendorIDs": [ + "GHSA-8w49-h785-mj3c" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.1", + "UID": "126e7ace3c7e0a17" + }, + "InstalledVersion": "6.4.1", + "FixedVersion": "6.4.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-52804", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a72dae9ebe67f33e556f7475ddbf55250ea99c809bf1e9c12a6ac4939ab3ce7f", + "Title": "python-tornado: Tornado has HTTP cookie parsing DoS vulnerability", + "Description": "Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "ghsa": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:10590", + "https://access.redhat.com/security/cve/CVE-2024-52804", + "https://bugzilla.redhat.com/2328045", + "https://bugzilla.redhat.com/show_bug.cgi?id=2328045", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52804", + "https://errata.almalinux.org/9/ALSA-2024-10590.html", + "https://errata.rockylinux.org/RLSA-2024:10590", + "https://github.com/advisories/GHSA-7pwv-g7hj-39pr", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/d5ba4a1695fbf7c6a3e54313262639b198291533", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-8w49-h785-mj3c", + "https://linux.oracle.com/cve/CVE-2024-52804.html", + "https://linux.oracle.com/errata/ELSA-2025-2872.html", + "https://lists.debian.org/debian-lts-announce/2025/01/msg00000.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-52804", + "https://ubuntu.com/security/notices/USN-7150-1", + "https://www.cve.org/CVERecord?id=CVE-2024-52804" + ], + "PublishedDate": "2024-11-22T16:15:34.417Z", + "LastModifiedDate": "2026-06-17T08:07:39.533Z" + }, + { + "VulnerabilityID": "CVE-2025-47287", + "VendorIDs": [ + "GHSA-7cx3-6m66-7c5m" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.1", + "UID": "126e7ace3c7e0a17" + }, + "InstalledVersion": "6.4.1", + "FixedVersion": "6.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47287", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:7c7072b4e55a7fc5fedac6e0c107a69c8dca7d6754e93714b7a0afd119ef32f1", + "Title": "tornado: Tornado Multipart Form-Data Denial of Service", + "Description": "Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "ghsa": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:8136", + "https://access.redhat.com/security/cve/CVE-2025-47287", + "https://bugzilla.redhat.com/2366703", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366703", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47287", + "https://errata.almalinux.org/9/ALSA-2025-8136.html", + "https://errata.rockylinux.org/RLSA-2025:8136", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/b39b892bf78fe8fea01dd45199aa88307e7162f3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5m", + "https://linux.oracle.com/cve/CVE-2025-47287.html", + "https://linux.oracle.com/errata/ELSA-2025-8664.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00038.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47287", + "https://ubuntu.com/security/notices/USN-7547-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47287" + ], + "PublishedDate": "2025-05-15T22:15:18.827Z", + "LastModifiedDate": "2026-06-17T09:27:40.32Z" + }, + { + "VulnerabilityID": "CVE-2025-67725", + "VendorIDs": [ + "GHSA-c98p-7wgm-6p64" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.1", + "UID": "126e7ace3c7e0a17" + }, + "InstalledVersion": "6.4.1", + "FixedVersion": "6.5.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-67725", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:ac3de2df76552d219792ce5765df5aa0802d829753c0010d44c922b4556ef2ff", + "Title": "tornado: Tornado Quadratic DoS via Repeated Header Coalescing", + "Description": "Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS). Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if max_header_size has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0930", + "https://access.redhat.com/security/cve/CVE-2025-67725", + "https://bugzilla.redhat.com/2421722", + "https://bugzilla.redhat.com/2421733", + "https://errata.almalinux.org/8/ALSA-2026-0930.html", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-266.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c98p-7wgm-6p64", + "https://linux.oracle.com/cve/CVE-2025-67725.html", + "https://linux.oracle.com/errata/ELSA-2026-0930.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-67725", + "https://ubuntu.com/security/notices/USN-7950-1", + "https://www.cve.org/CVERecord?id=CVE-2025-67725" + ], + "PublishedDate": "2025-12-12T06:15:41.38Z", + "LastModifiedDate": "2026-06-17T09:58:02.337Z" + }, + { + "VulnerabilityID": "CVE-2025-67726", + "VendorIDs": [ + "GHSA-jhmp-mqwm-3gq8" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.1", + "UID": "126e7ace3c7e0a17" + }, + "InstalledVersion": "6.4.1", + "FixedVersion": "6.5.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-67726", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:052ac9be79c1539e80243e05745c284c06be69ad20bfc4f45bb86a4d725312aa", + "Title": "tornado: Tornado Quadratic DoS via Crafted Multipart Parameters", + "Description": "Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.py is used to parse specific HTTP header values, such as those in multipart/form-data and repeatedly calls string.count() within a nested loop while processing quoted semicolons. If an attacker sends a request with a large number of maliciously crafted parameters in a Content-Disposition header, the server's CPU usage increases quadratically (O(n²)) during parsing. Due to Tornado's single event loop architecture, a single malicious request can cause the entire server to become unresponsive for an extended period. This issue is fixed in version 6.5.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-834" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0930", + "https://access.redhat.com/security/cve/CVE-2025-67726", + "https://bugzilla.redhat.com/2421722", + "https://bugzilla.redhat.com/2421733", + "https://errata.almalinux.org/8/ALSA-2026-0930.html", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-267.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.3", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-jhmp-mqwm-3gq8", + "https://linux.oracle.com/cve/CVE-2025-67726.html", + "https://linux.oracle.com/errata/ELSA-2026-0930.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-67726", + "https://ubuntu.com/security/notices/USN-7950-1", + "https://www.cve.org/CVERecord?id=CVE-2025-67726" + ], + "PublishedDate": "2025-12-12T07:15:44.92Z", + "LastModifiedDate": "2026-06-17T09:58:02.44Z" + }, + { + "VulnerabilityID": "CVE-2026-31958", + "VendorIDs": [ + "GHSA-qjxf-f2mg-c6mc" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.1", + "UID": "126e7ace3c7e0a17" + }, + "InstalledVersion": "6.4.1", + "FixedVersion": "6.5.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-31958", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:82adf7fddc932bda34860ffbb6c57c23cd3ff98263b2d1eabedf0cbba90cd022", + "Title": "tornado-python: Tornado: Denial of Service via large multipart bodies", + "Description": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:19189", + "https://access.redhat.com/security/cve/CVE-2026-31958", + "https://bugzilla.redhat.com/2446765", + "https://bugzilla.redhat.com/2454716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", + "https://bugzilla.redhat.com/show_bug.cgi?id=2454716", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31958", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35536", + "https://errata.almalinux.org/9/ALSA-2026-19189.html", + "https://errata.rockylinux.org/RLSA-2026:19189", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2026-140.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc", + "https://linux.oracle.com/cve/CVE-2026-31958.html", + "https://linux.oracle.com/errata/ELSA-2026-8093.html", + "https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-31958", + "https://ubuntu.com/security/notices/USN-8198-1", + "https://ubuntu.com/security/notices/USN-8198-2", + "https://www.cve.org/CVERecord?id=CVE-2026-31958" + ], + "PublishedDate": "2026-03-11T20:16:16.617Z", + "LastModifiedDate": "2026-06-17T10:34:50.473Z" + }, + { + "VulnerabilityID": "CVE-2026-35536", + "VendorIDs": [ + "GHSA-fqwm-6jpj-5wxc" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.1", + "UID": "126e7ace3c7e0a17" + }, + "InstalledVersion": "6.4.1", + "FixedVersion": "6.5.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-35536", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:302472eb8d07ea132c9177c177abc015c20c5cf435cdb07a424c4165cb840231", + "Title": "tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments", + "Description": "In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-159" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "photon": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N", + "V3Score": 7.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", + "V3Score": 5.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:19189", + "https://access.redhat.com/security/cve/CVE-2026-35536", + "https://bugzilla.redhat.com/2446765", + "https://bugzilla.redhat.com/2454716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", + "https://bugzilla.redhat.com/show_bug.cgi?id=2454716", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31958", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35536", + "https://errata.almalinux.org/9/ALSA-2026-19189.html", + "https://errata.rockylinux.org/RLSA-2026:19189", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7", + "https://linux.oracle.com/cve/CVE-2026-35536.html", + "https://linux.oracle.com/errata/ELSA-2026-24342.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-35536", + "https://ubuntu.com/security/notices/USN-8198-1", + "https://ubuntu.com/security/notices/USN-8198-2", + "https://www.cve.org/CVERecord?id=CVE-2026-35536" + ], + "PublishedDate": "2026-04-03T04:16:53.55Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-49853", + "VendorIDs": [ + "GHSA-3x9g-8vmp-wqvf" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.1", + "UID": "126e7ace3c7e0a17" + }, + "InstalledVersion": "6.4.1", + "FixedVersion": "6.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49853", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3393a197a85d7af4e4426b0e448ed0ed165620fadd269077fabcf1c225222b44", + "Title": "Tornado is a Python web framework and asynchronous networking library. ...", + "Description": "Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "photon": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 7.7 + } + }, + "References": [ + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/aba2569f7ed7a6bdbef816658fb6b7182531b751", + "https://github.com/tornadoweb/tornado/pull/3626", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.6", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf" + ], + "PublishedDate": "2026-07-14T21:17:02.13Z", + "LastModifiedDate": "2026-07-21T16:17:13.477Z" + }, + { + "VulnerabilityID": "CVE-2026-49855", + "VendorIDs": [ + "GHSA-mgf9-4vpg-hj56" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.4.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.4.1", + "UID": "126e7ace3c7e0a17" + }, + "InstalledVersion": "6.4.1", + "FixedVersion": "6.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49855", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a913e7058a708b5c9d4757a49cb39fe3819c346d49e33729da38d1b51316bc6b", + "Title": "Tornado is a Python web framework and asynchronous networking library. ...", + "Description": "Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "photon": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff", + "https://github.com/tornadoweb/tornado/pull/3626", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56" + ], + "PublishedDate": "2026-07-14T21:17:02.437Z", + "LastModifiedDate": "2026-07-16T16:19:10.69Z" + }, + { + "VulnerabilityID": "CVE-2025-66418", + "VendorIDs": [ + "GHSA-gm62-xv2j-4w53" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.2.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.1", + "UID": "f930d1e7cfeacf0f" + }, + "InstalledVersion": "2.2.1", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66418", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:6e29ff20dfad33276a38feea3285d548a9e933a90a12221c95363d3db69e020e", + "Title": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66418", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53", + "https://linux.oracle.com/cve/CVE-2025-66418.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66418", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://www.cve.org/CVERecord?id=CVE-2025-66418", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T16:15:51.053Z", + "LastModifiedDate": "2026-06-17T09:56:48.383Z" + }, + { + "VulnerabilityID": "CVE-2025-66471", + "VendorIDs": [ + "GHSA-2xpw-w6gg-jr37" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.2.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.1", + "UID": "f930d1e7cfeacf0f" + }, + "InstalledVersion": "2.2.1", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66471", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9637ebb223b4fe8d966c6d3b81f823ccc9ac16fb1210053ed00775d4b8f95a2f", + "Title": "urllib3: urllib3 Streaming API improperly handles highly compressed data", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66471", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37", + "https://linux.oracle.com/cve/CVE-2025-66471.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66471", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-7927-2", + "https://ubuntu.com/security/notices/USN-7927-3", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://ubuntu.com/security/notices/USN-8344-2", + "https://ubuntu.com/security/notices/USN-8344-3", + "https://www.cve.org/CVERecord?id=CVE-2025-66471", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T17:16:04.4Z", + "LastModifiedDate": "2026-06-17T09:56:53.65Z" + }, + { + "VulnerabilityID": "CVE-2026-21441", + "VendorIDs": [ + "GHSA-38jv-5279-wg99" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.2.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.1", + "UID": "f930d1e7cfeacf0f" + }, + "InstalledVersion": "2.2.1", + "FixedVersion": "2.6.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-21441", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:ef5acf3eb8345f8480f4c4da918070c822ffdfd6b12de5e92b64a4c5f2a7dfc3", + "Title": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)", + "Description": "urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V3Score": 7.5, + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0981", + "https://access.redhat.com/errata/RHSA-2026:0990", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:1038", + "https://access.redhat.com/errata/RHSA-2026:1041", + "https://access.redhat.com/errata/RHSA-2026:1042", + "https://access.redhat.com/errata/RHSA-2026:1086", + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1088", + "https://access.redhat.com/errata/RHSA-2026:1089", + "https://access.redhat.com/errata/RHSA-2026:1166", + "https://access.redhat.com/errata/RHSA-2026:1168", + "https://access.redhat.com/errata/RHSA-2026:1176", + "https://access.redhat.com/errata/RHSA-2026:1224", + "https://access.redhat.com/errata/RHSA-2026:1226", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/errata/RHSA-2026:1240", + "https://access.redhat.com/errata/RHSA-2026:1241", + "https://access.redhat.com/errata/RHSA-2026:1254", + "https://access.redhat.com/errata/RHSA-2026:1485", + "https://access.redhat.com/errata/RHSA-2026:14877", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:1546", + "https://access.redhat.com/errata/RHSA-2026:1596", + "https://access.redhat.com/errata/RHSA-2026:1599", + "https://access.redhat.com/errata/RHSA-2026:1609", + "https://access.redhat.com/errata/RHSA-2026:1618", + "https://access.redhat.com/errata/RHSA-2026:1619", + "https://access.redhat.com/errata/RHSA-2026:1652", + "https://access.redhat.com/errata/RHSA-2026:1674", + "https://access.redhat.com/errata/RHSA-2026:1676", + "https://access.redhat.com/errata/RHSA-2026:1693", + "https://access.redhat.com/errata/RHSA-2026:1704", + "https://access.redhat.com/errata/RHSA-2026:1706", + "https://access.redhat.com/errata/RHSA-2026:1712", + "https://access.redhat.com/errata/RHSA-2026:1717", + "https://access.redhat.com/errata/RHSA-2026:1726", + "https://access.redhat.com/errata/RHSA-2026:1729", + "https://access.redhat.com/errata/RHSA-2026:1730", + "https://access.redhat.com/errata/RHSA-2026:1734", + "https://access.redhat.com/errata/RHSA-2026:1735", + "https://access.redhat.com/errata/RHSA-2026:1736", + "https://access.redhat.com/errata/RHSA-2026:17456", + "https://access.redhat.com/errata/RHSA-2026:17457", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17461", + "https://access.redhat.com/errata/RHSA-2026:17462", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:1791", + "https://access.redhat.com/errata/RHSA-2026:1792", + "https://access.redhat.com/errata/RHSA-2026:1793", + "https://access.redhat.com/errata/RHSA-2026:1794", + "https://access.redhat.com/errata/RHSA-2026:1803", + "https://access.redhat.com/errata/RHSA-2026:1805", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:1957", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2126", + "https://access.redhat.com/errata/RHSA-2026:2137", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2144", + "https://access.redhat.com/errata/RHSA-2026:2256", + "https://access.redhat.com/errata/RHSA-2026:2456", + "https://access.redhat.com/errata/RHSA-2026:2500", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:2563", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2717", + "https://access.redhat.com/errata/RHSA-2026:2718", + "https://access.redhat.com/errata/RHSA-2026:2723", + "https://access.redhat.com/errata/RHSA-2026:2728", + "https://access.redhat.com/errata/RHSA-2026:2760", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2764", + "https://access.redhat.com/errata/RHSA-2026:2765", + "https://access.redhat.com/errata/RHSA-2026:28043", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2911", + "https://access.redhat.com/errata/RHSA-2026:2919", + "https://access.redhat.com/errata/RHSA-2026:2924", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:2926", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:33154", + "https://access.redhat.com/errata/RHSA-2026:3406", + "https://access.redhat.com/errata/RHSA-2026:3444", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:44696", + "https://access.redhat.com/errata/RHSA-2026:51357", + "https://access.redhat.com/errata/RHSA-2026:5459", + "https://access.redhat.com/errata/RHSA-2026:6287", + "https://access.redhat.com/errata/RHSA-2026:6292", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8500", + "https://access.redhat.com/errata/RHSA-2026:8501", + "https://access.redhat.com/security/cve/CVE-2026-21441", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99", + "https://linux.oracle.com/cve/CVE-2026-21441.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-21441", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json", + "https://ubuntu.com/security/notices/USN-7955-1", + "https://ubuntu.com/security/notices/USN-7955-2", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2026-21441" + ], + "PublishedDate": "2026-01-07T22:15:44.04Z", + "LastModifiedDate": "2026-08-14T13:17:38.737Z" + }, + { + "VulnerabilityID": "CVE-2026-44431", + "VendorIDs": [ + "GHSA-qccp-gfcp-xxvc" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.2.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.1", + "UID": "f930d1e7cfeacf0f" + }, + "InstalledVersion": "2.2.1", + "FixedVersion": "2.7.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44431", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:eb7ab8ffd11eb568c6a7118cf7bf9e14bd026f00594aae469ac372f09e735171", + "Title": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers", + "Description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V3Score": 5.3, + "V40Score": 8.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:28158", + "https://access.redhat.com/errata/RHSA-2026:28159", + "https://access.redhat.com/security/cve/CVE-2026-44431", + "https://bugzilla.redhat.com/2477154", + "https://bugzilla.redhat.com/2477167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477154", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477167", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432", + "https://errata.almalinux.org/9/ALSA-2026-28159.html", + "https://errata.rockylinux.org/RLSA-2026:28158", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc", + "https://linux.oracle.com/cve/CVE-2026-44431.html", + "https://linux.oracle.com/errata/ELSA-2026-49927.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44431", + "https://ubuntu.com/security/notices/USN-8379-1", + "https://www.cve.org/CVERecord?id=CVE-2026-44431" + ], + "PublishedDate": "2026-05-13T16:16:57.15Z", + "LastModifiedDate": "2026-06-26T12:16:32.423Z" + }, + { + "VulnerabilityID": "CVE-2026-24049", + "VendorIDs": [ + "GHSA-8rrh-rw8j-w5fx" + ], + "PkgName": "wheel", + "PkgPath": "usr/local/lib/python3.12/site-packages/wheel-0.43.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/wheel@0.43.0", + "UID": "3f402770d505f8b0" + }, + "InstalledVersion": "0.43.0", + "FixedVersion": "0.46.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-24049", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:02e2441d114381bec6ed49959433315423b7c4c3d4181e22239d775d4c45c89c", + "Title": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking", + "Description": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22", + "CWE-732" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", + "V3Score": 5.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:1902", + "https://access.redhat.com/errata/RHSA-2026:1939", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:2090", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2675", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2694", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2710", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2823", + "https://access.redhat.com/errata/RHSA-2026:2865", + "https://access.redhat.com/errata/RHSA-2026:2866", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5119", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6555", + "https://access.redhat.com/errata/RHSA-2026:6562", + "https://access.redhat.com/errata/RHSA-2026:6565", + "https://access.redhat.com/errata/RHSA-2026:7250", + "https://access.redhat.com/security/cve/CVE-2026-24049", + "https://bugzilla.redhat.com/2431959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2431959", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24049", + "https://errata.almalinux.org/9/ALSA-2026-1939.html", + "https://errata.rockylinux.org/RLSA-2026:1939", + "https://github.com/pypa/wheel", + "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef", + "https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e", + "https://github.com/pypa/wheel/releases/tag/0.46.2", + "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx", + "https://linux.oracle.com/cve/CVE-2026-24049.html", + "https://linux.oracle.com/errata/ELSA-2026-2090.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-24049", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json", + "https://ubuntu.com/security/notices/USN-8221-1", + "https://www.cve.org/CVERecord?id=CVE-2026-24049" + ], + "PublishedDate": "2026-01-22T05:16:23.157Z", + "LastModifiedDate": "2026-08-12T12:17:55.967Z" + }, + { + "VulnerabilityID": "CVE-2026-56852", + "VendorIDs": [ + "GO-2026-5970" + ], + "PkgID": "golang.org/x/text@v0.14.0", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.14.0", + "UID": "4a2c7ca051ae9b50" + }, + "InstalledVersion": "v0.14.0", + "FixedVersion": "0.39.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56852", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8e979f0919a35e5a8b0ad0687968390f2176b77358c16459491a51f057c04c70", + "Title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input", + "Description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56852", + "https://go.dev/cl/794100", + "https://go.dev/issue/80142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56852", + "https://pkg.go.dev/vuln/GO-2026-5970", + "https://www.cve.org/CVERecord?id=CVE-2026-56852" + ], + "PublishedDate": "2026-07-21T20:17:02.867Z", + "LastModifiedDate": "2026-07-23T18:27:48.877Z" + }, + { + "VulnerabilityID": "CVE-2024-24790", + "VendorIDs": [ + "GO-2024-2887" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.21.11, 1.22.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-24790", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:dcaf283477c6288813bac3705a13479005a614e676adf5893a800bbef37a8a29", + "Title": "golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses", + "Description": "The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.", + "Severity": "CRITICAL", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "bottlerocket": 2, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.7 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "http://www.openwall.com/lists/oss-security/2024/06/04/1", + "https://access.redhat.com/errata/RHSA-2025:7256", + "https://access.redhat.com/security/cve/CVE-2024-24790", + "https://bugzilla.redhat.com/2237777", + "https://bugzilla.redhat.com/2237778", + "https://bugzilla.redhat.com/2279814", + "https://bugzilla.redhat.com/2292787", + "https://bugzilla.redhat.com/2295310", + "https://bugzilla.redhat.com/2315719", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2279814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2292787", + "https://bugzilla.redhat.com/show_bug.cgi?id=2295310", + "https://bugzilla.redhat.com/show_bug.cgi?id=2315719", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24788", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24791", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9355", + "https://errata.almalinux.org/9/ALSA-2025-7256.html", + "https://errata.rockylinux.org/RLSA-2025:7256", + "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/2.9.0/BRSA-glvb5gspjgq6.toml", + "https://github.com/golang/go/commit/051bdf3fd12a40307606ff9381138039c5f452f0%20%281.21%29", + "https://github.com/golang/go/commit/12d5810cdb1f73cf23d7a86462143e9463317fca%20%281.22%29", + "https://github.com/golang/go/issues/67680", + "https://go.dev/cl/590316", + "https://go.dev/issue/67680", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ", + "https://linux.oracle.com/cve/CVE-2024-24790.html", + "https://linux.oracle.com/errata/ELSA-2025-7256.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-24790", + "https://pkg.go.dev/vuln/GO-2024-2887", + "https://security.netapp.com/advisory/ntap-20240905-0002/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2024-24790" + ], + "PublishedDate": "2024-06-05T16:15:10.56Z", + "LastModifiedDate": "2026-06-17T07:14:52.097Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b2957aaf99c4806817c3ae5700c29de54ab1dec5e9d0548dbb1bde9ada09a1a4", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2024-34156", + "VendorIDs": [ + "GO-2024-3106" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.22.7, 1.23.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-34156", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:46c369ca6b5f45178ca9790b6ae32e394785acf9db922bbc82aa320cc15be986", + "Title": "encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion", + "Description": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:3773", + "https://access.redhat.com/security/cve/CVE-2024-34156", + "https://bugzilla.redhat.com/2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341750", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341751", + "https://bugzilla.redhat.com/show_bug.cgi?id=2344219", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866", + "https://errata.almalinux.org/9/ALSA-2025-3773.html", + "https://errata.rockylinux.org/RLSA-2025:3773", + "https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01%20%28go1.22.7%29", + "https://github.com/golang/go/commit/fa8ff1a46deb6c816304441ec6740ec112e19012%20%28go1.23.1%29", + "https://go.dev/cl/611239", + "https://go.dev/issue/69139", + "https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc", + "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk", + "https://linux.oracle.com/cve/CVE-2024-34156.html", + "https://linux.oracle.com/errata/ELSA-2025-3773.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-34156", + "https://pkg.go.dev/vuln/GO-2024-3106", + "https://security.netapp.com/advisory/ntap-20240926-0004/", + "https://ubuntu.com/security/notices/USN-7081-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2024-34156" + ], + "PublishedDate": "2024-09-06T21:15:12.02Z", + "LastModifiedDate": "2026-06-17T07:33:00.72Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ec16ff99b82ce67f72e89a6c3b8978b82f595e8ec2815e86f4eb51a2b1346074", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-08-14T13:17:15.67Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f9b66f8d912cdb0a06e9502c891de5d9b77cd1a186b3c57eefb786d74aedca2f", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:bcebe0e69fae3b64e69c6c7c29d52baabf60be98548ca0879b9f0e1c678e8b4e", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-08-14T13:17:46.517Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f8474c09cee4380b51fb9c111f56adcea3757f5a6b30da484e00a2a571a81244", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-08-14T13:17:49.537Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:81a3829b51d0fcb03d0c9210a96164c1bf8cd099c82fac48adb66388d4d74dfd", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-08-14T13:17:52.587Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:fd645cf701714c17d5168f7ab92c8efaadb49f71a3bf50fbe74cd3a742a41dac", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:55aeb7c7eeae4af39c33273edb0774b220cfb8d7edbd6f3f297b7c64afdf1aa8", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-33722.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-08-14T13:17:54.66Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ba48455885770a8f686489a300fa26fc1738d742907f1cdd8271685843d6aac4", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:39319", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-39573.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-08-14T13:18:12Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3ed0898585ab788e43124abc5d51e766deb4c67aca0f2f82082b1855196e095a", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-08-13T13:18:25.52Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b2eac4619a59e6b6eda63e4fcb33e61202c21a25a94d0e16200617a95289df07", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-08-14T16:16:55.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4b4dae3a6285c20a9be5fc7587cd2a336b8fb9b823693e9930c5bcdf0e5a0312", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-08-14T13:18:23.657Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:22950d5f6a5f4983f80ce2f4a16ca81f198d945fd931be92f9be14c4b627d135", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:37435", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-08-14T13:18:24.667Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:309d756aeb5d2aaa7b5b3d2d6962f48d46436fa5fe373b51f6e1a874db6b7d27", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:073344153ca4e7c1b3ed81cebc3dff2a725359ab076131fcf06764277d1b02ae", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7657a2f07d58e2e2be3edfa4f3fc2fec79fe3fc2c5f704353060e0c45379e342", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-08-14T13:18:47.497Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8af084b6240e1adfd92fb1bec98e2a0974185d5e15eac29a1a9596afb9525f7a", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4c81f0747e7a0188fac252836ca9139a99c7b4fc824b1b62b0545db2dcb0117a", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-08-14T16:16:57.21Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4c9d275f2c825fef40c8462b93dcf37f3c71279c16afdc123122d8d6641fbf2b", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-08-14T16:16:57.367Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e6289c1bdfa7aa82674480dda23425a8bd7a58854d5c4574011e2ec305f664fb", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-08-14T16:16:57.523Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:dcacb262b8832ccd84765818253f0bdce7956a4503c0b489e8ee185c67bf919b", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-08-14T17:19:13.91Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "e6283c14bc733976" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ed742404784e40a8a0711da20d1f4f4dbb81dc3f9f78703c58a76b30e89d9eae", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-08-14T16:16:57.717Z" + }, + { + "VulnerabilityID": "CVE-2026-56852", + "VendorIDs": [ + "GO-2026-5970" + ], + "PkgID": "golang.org/x/text@v0.14.0", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.14.0", + "UID": "3bfe12269221baa9" + }, + "InstalledVersion": "v0.14.0", + "FixedVersion": "0.39.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56852", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:92c51447d1de40c10b820e6219a5a067393f9e4a4331c85555e0b604a379eb6d", + "Title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input", + "Description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56852", + "https://go.dev/cl/794100", + "https://go.dev/issue/80142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56852", + "https://pkg.go.dev/vuln/GO-2026-5970", + "https://www.cve.org/CVERecord?id=CVE-2026-56852" + ], + "PublishedDate": "2026-07-21T20:17:02.867Z", + "LastModifiedDate": "2026-07-23T18:27:48.877Z" + }, + { + "VulnerabilityID": "CVE-2024-24790", + "VendorIDs": [ + "GO-2024-2887" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.21.11, 1.22.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-24790", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:79f214618384de23c61334386d0ee25c6a569a7e9033310747119b3fba4f7c28", + "Title": "golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses", + "Description": "The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.", + "Severity": "CRITICAL", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "bottlerocket": 2, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.7 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "http://www.openwall.com/lists/oss-security/2024/06/04/1", + "https://access.redhat.com/errata/RHSA-2025:7256", + "https://access.redhat.com/security/cve/CVE-2024-24790", + "https://bugzilla.redhat.com/2237777", + "https://bugzilla.redhat.com/2237778", + "https://bugzilla.redhat.com/2279814", + "https://bugzilla.redhat.com/2292787", + "https://bugzilla.redhat.com/2295310", + "https://bugzilla.redhat.com/2315719", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2279814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2292787", + "https://bugzilla.redhat.com/show_bug.cgi?id=2295310", + "https://bugzilla.redhat.com/show_bug.cgi?id=2315719", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24788", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24791", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9355", + "https://errata.almalinux.org/9/ALSA-2025-7256.html", + "https://errata.rockylinux.org/RLSA-2025:7256", + "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/2.9.0/BRSA-glvb5gspjgq6.toml", + "https://github.com/golang/go/commit/051bdf3fd12a40307606ff9381138039c5f452f0%20%281.21%29", + "https://github.com/golang/go/commit/12d5810cdb1f73cf23d7a86462143e9463317fca%20%281.22%29", + "https://github.com/golang/go/issues/67680", + "https://go.dev/cl/590316", + "https://go.dev/issue/67680", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ", + "https://linux.oracle.com/cve/CVE-2024-24790.html", + "https://linux.oracle.com/errata/ELSA-2025-7256.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-24790", + "https://pkg.go.dev/vuln/GO-2024-2887", + "https://security.netapp.com/advisory/ntap-20240905-0002/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2024-24790" + ], + "PublishedDate": "2024-06-05T16:15:10.56Z", + "LastModifiedDate": "2026-06-17T07:14:52.097Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4e8f73f21dea764bdaa33d572f2ff431e4f582fd929641147b962af1dd7ab5da", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2024-34156", + "VendorIDs": [ + "GO-2024-3106" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.22.7, 1.23.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-34156", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:187b7c4b0c2b9aea3e0c6b0843e18d09e647d783b76a114fb4328f7d3954f390", + "Title": "encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion", + "Description": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:3773", + "https://access.redhat.com/security/cve/CVE-2024-34156", + "https://bugzilla.redhat.com/2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341750", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341751", + "https://bugzilla.redhat.com/show_bug.cgi?id=2344219", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866", + "https://errata.almalinux.org/9/ALSA-2025-3773.html", + "https://errata.rockylinux.org/RLSA-2025:3773", + "https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01%20%28go1.22.7%29", + "https://github.com/golang/go/commit/fa8ff1a46deb6c816304441ec6740ec112e19012%20%28go1.23.1%29", + "https://go.dev/cl/611239", + "https://go.dev/issue/69139", + "https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc", + "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk", + "https://linux.oracle.com/cve/CVE-2024-34156.html", + "https://linux.oracle.com/errata/ELSA-2025-3773.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-34156", + "https://pkg.go.dev/vuln/GO-2024-3106", + "https://security.netapp.com/advisory/ntap-20240926-0004/", + "https://ubuntu.com/security/notices/USN-7081-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2024-34156" + ], + "PublishedDate": "2024-09-06T21:15:12.02Z", + "LastModifiedDate": "2026-06-17T07:33:00.72Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:282c81d4bda2caf82b78c8edcd7c7d6d89d593b23ff0bec7dc4c9a0ffc663b57", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-08-14T13:17:15.67Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:45285355e0089dd4a910de06d33e46f49efb70eeb2430c7c6c2c0b5dc6608fe8", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f9479b6bf2d9526738c6a6f2dfd3c11d0514dae593f1b3445f53c5993b8b849b", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-08-14T13:17:46.517Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2c4adab22c1886cedd484a03b0ae90f1025d67ff437ecabfb5413ff35841fe25", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-08-14T13:17:49.537Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a6a98120c3ecbc1934c8244a6a4a9ae021eb1c57725190c5d937e8653b251faf", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-08-14T13:17:52.587Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:fffb39e73b44c2ec7e6153367318e43315c2e7f21e676c634e0e12c59dc91795", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a449cfb3af7bf13989855efd4ac99d0e40ab118be5ebcd54aa20f55463349355", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-33722.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-08-14T13:17:54.66Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:857850b5c2ccfc86ec80b5eecd13275f1b3023bf2bf310a9c4b3ed0fb5baff2c", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:39319", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-39573.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-08-14T13:18:12Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1f2b7fe484a829e701733d5511b1b489a0583fbaea748f7fb9ff5d6d3478a8a0", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-08-13T13:18:25.52Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1fb122376c789cb223440dfce9c77569c1b62f842b2c5bc75ad5fdd9e54f7bfe", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-08-14T16:16:55.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a6ac37275e12e9ce7ef5f7b89948777b87dd4000431b91108f8b07b5311bd8e0", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-08-14T13:18:23.657Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1fc43c553a3bd4610837df1b58dd40f16c0c81a2f057902511af5ecbc1d6e053", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:37435", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-08-14T13:18:24.667Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:17afaf6971bb78a4d8b80aa200d15646a9f86e7a2df4452cc832119623ae3b63", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f039839fea04ea5d8fc6a9adefe7638a2f9a390abe68df2b5c4f1c208bc6e5e2", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f2362f488fe25bf1fa3fb5806fa9099582cd8399eff9f0756c0a469770ae32b3", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-08-14T13:18:47.497Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:236e9a6b058c76f983cefdca577320683de48f2dd7d9d024ed12729097a248be", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:665c63a9d77203c1c6e1b0207a97be88dc81b3565cc4346c356fe8e01e652053", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-08-14T16:16:57.21Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d1ce8571c65046c7bfc2731c69e632ebc9e70bbde0cf99fd04738ee6a4313aa2", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-08-14T16:16:57.367Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2eb9be4f3f7b761a3084fdb381f50cbaa15ebbedce712b351f668c839b761838", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-08-14T16:16:57.523Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8283f23d7042699690f044c09ca0d12b225b520c244531a7aa28639aa24c53f3", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-08-14T17:19:13.91Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "1919d38f0e3f881b" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0038bd74bea3118589ab7cbd5d85a33ad773d8645a94e783458cee8d872a9641", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-08-14T16:16:57.717Z" + }, + { + "VulnerabilityID": "CVE-2026-56852", + "VendorIDs": [ + "GO-2026-5970" + ], + "PkgID": "golang.org/x/text@v0.14.0", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.14.0", + "UID": "311aa3df90440407" + }, + "InstalledVersion": "v0.14.0", + "FixedVersion": "0.39.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56852", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f38ad7088548b21699bce7b53f34b52b5aaab03cc09dcc947dbd85e011ba92fc", + "Title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input", + "Description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56852", + "https://go.dev/cl/794100", + "https://go.dev/issue/80142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56852", + "https://pkg.go.dev/vuln/GO-2026-5970", + "https://www.cve.org/CVERecord?id=CVE-2026-56852" + ], + "PublishedDate": "2026-07-21T20:17:02.867Z", + "LastModifiedDate": "2026-07-23T18:27:48.877Z" + }, + { + "VulnerabilityID": "CVE-2024-24790", + "VendorIDs": [ + "GO-2024-2887" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.21.11, 1.22.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-24790", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:cacf08bc69530f3be54709461b6b861d651d036729a4eba52398f660b998bdbd", + "Title": "golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses", + "Description": "The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.", + "Severity": "CRITICAL", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "bottlerocket": 2, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.7 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "http://www.openwall.com/lists/oss-security/2024/06/04/1", + "https://access.redhat.com/errata/RHSA-2025:7256", + "https://access.redhat.com/security/cve/CVE-2024-24790", + "https://bugzilla.redhat.com/2237777", + "https://bugzilla.redhat.com/2237778", + "https://bugzilla.redhat.com/2279814", + "https://bugzilla.redhat.com/2292787", + "https://bugzilla.redhat.com/2295310", + "https://bugzilla.redhat.com/2315719", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2279814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2292787", + "https://bugzilla.redhat.com/show_bug.cgi?id=2295310", + "https://bugzilla.redhat.com/show_bug.cgi?id=2315719", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24788", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24791", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9355", + "https://errata.almalinux.org/9/ALSA-2025-7256.html", + "https://errata.rockylinux.org/RLSA-2025:7256", + "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/2.9.0/BRSA-glvb5gspjgq6.toml", + "https://github.com/golang/go/commit/051bdf3fd12a40307606ff9381138039c5f452f0%20%281.21%29", + "https://github.com/golang/go/commit/12d5810cdb1f73cf23d7a86462143e9463317fca%20%281.22%29", + "https://github.com/golang/go/issues/67680", + "https://go.dev/cl/590316", + "https://go.dev/issue/67680", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ", + "https://linux.oracle.com/cve/CVE-2024-24790.html", + "https://linux.oracle.com/errata/ELSA-2025-7256.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-24790", + "https://pkg.go.dev/vuln/GO-2024-2887", + "https://security.netapp.com/advisory/ntap-20240905-0002/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2024-24790" + ], + "PublishedDate": "2024-06-05T16:15:10.56Z", + "LastModifiedDate": "2026-06-17T07:14:52.097Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:938c70dce155a5b1d21c33e20c561c3e1320d73d1d70caff844b631306f55d9f", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2024-34156", + "VendorIDs": [ + "GO-2024-3106" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.22.7, 1.23.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-34156", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c4d30e38459863e137f7b2257fa2c3b70dc1b5bc8c3ffd023f00f73fdbc3cb28", + "Title": "encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion", + "Description": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:3773", + "https://access.redhat.com/security/cve/CVE-2024-34156", + "https://bugzilla.redhat.com/2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341750", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341751", + "https://bugzilla.redhat.com/show_bug.cgi?id=2344219", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866", + "https://errata.almalinux.org/9/ALSA-2025-3773.html", + "https://errata.rockylinux.org/RLSA-2025:3773", + "https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01%20%28go1.22.7%29", + "https://github.com/golang/go/commit/fa8ff1a46deb6c816304441ec6740ec112e19012%20%28go1.23.1%29", + "https://go.dev/cl/611239", + "https://go.dev/issue/69139", + "https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc", + "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk", + "https://linux.oracle.com/cve/CVE-2024-34156.html", + "https://linux.oracle.com/errata/ELSA-2025-3773.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-34156", + "https://pkg.go.dev/vuln/GO-2024-3106", + "https://security.netapp.com/advisory/ntap-20240926-0004/", + "https://ubuntu.com/security/notices/USN-7081-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2024-34156" + ], + "PublishedDate": "2024-09-06T21:15:12.02Z", + "LastModifiedDate": "2026-06-17T07:33:00.72Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:08b3a2c7f4d8c621ac57c1ccf54176cd7d716b2371e730608415edee876391f5", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-08-14T13:17:15.67Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:308c96a849c1720a6da462054689d94150b593797a94de9a0175d1d68b20b212", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7f06d6f8cd05a7cfd89da6cc9f1fc91dc0c6b70c22cd1d84bf1a5cf08f470fe1", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-08-14T13:17:46.517Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:dac338c2fcd05dcabb3e14f06e76875d7183ea24bba568005d3efcbc41230729", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-08-14T13:17:49.537Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:391c60bb161c08a954fb6e71390162b5116ef04d600d05c23340c1cbc6dd6db4", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-08-14T13:17:52.587Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f63a8befebca72e949617b02162b8cee9a68f02a2c2cf4b0b490b6a216af050d", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1d092380b31e403d4f0536aeca5b3e3cadda01d72e7d20da472b12fef8630297", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-33722.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-08-14T13:17:54.66Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6d86be16216bf75f0996de4a99502634ac3420c826608e69b216eddf2ec4a232", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:39319", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-39573.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-08-14T13:18:12Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:faf92f79fc096555f394b812b9784bab021c4c98c60265f7b8d3f639972fb052", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-08-13T13:18:25.52Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0881644d4410145115fc5a0538ce8383ebb82584a4e4c72c2a07dd60b055eee1", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-08-14T16:16:55.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a58db01e0150ef2000aa5ac8607a0c60c29b9cce681eae663dfcf5a50e95e320", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-08-14T13:18:23.657Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d4a442e7670b1334c983abb97a2fc52c880c9f53678427ac6f5b6eeeab7b3253", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:37435", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-08-14T13:18:24.667Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3837cb3ab66147bb842acd153ab7062c89cfebff28be74770baf297f8f477bfb", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:411788fe8be8ae8ac5b9d6162f19168f6ba3bdba0c8c12c7518d2560a95a6ceb", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4ddf53194ce422b5065e1b24560022c3d0979b31d0930191a7621ff1593b9bbc", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-08-14T13:18:47.497Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d8c6dc7d9bbfa755a765524109e4991b7dca7a8a8cbd4021cccada7fab8c4227", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:77623010925cb999629a37490cadabbb640a11426763c0c3b7e9de950ceba1b9", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-08-14T16:16:57.21Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:fceefa94df0ab4f899b867fd02df0908ae7c10148c54f3f3a85364dc415e20f7", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-08-14T16:16:57.367Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c00dc9f357a209feb72615d1762cac294e0b2bd1a4b009d40d64b7f3a39a2482", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-08-14T16:16:57.523Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a50d32714307626257815f80950718854fce6e06b7ad3524b01c68a3eb675918", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-08-14T17:19:13.91Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.22.3", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.22.3", + "UID": "ed8e8344d8aac3f9" + }, + "InstalledVersion": "v1.22.3", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e50282bb16dac2369dac76d9b3f2610fb813fc2aa2a4574141ad0087f75d7dc0", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-08-14T16:16:57.717Z" + }, + { + "VulnerabilityID": "CVE-2023-24538", + "VendorIDs": [ + "GO-2023-1703" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24538", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0f45fc4915e6330bb26339025e4bfe67dfd7a10bee4e32c3391cd96b0d159db1", + "Title": "golang: html/template: backticks not treated as string delimiters", + "Description": "Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. \"var a = {{.}}\"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24538", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/20374d1d759bc4e17486bde1cb9dca5be37d9e52%20%28go1.20.3%29", + "https://github.com/golang/go/commit/b1e3ecfa06b67014429a197ec5e134ce4303ad9b%20%28go1.19.8%29", + "https://github.com/golang/go/issues/59234", + "https://go.dev/cl/482079", + "https://go.dev/issue/59234", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24538.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24538", + "https://pkg.go.dev/vuln/GO-2023-1703", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241115-0007/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24538" + ], + "PublishedDate": "2023-04-06T16:15:07.8Z", + "LastModifiedDate": "2026-06-17T05:39:29.67Z" + }, + { + "VulnerabilityID": "CVE-2023-24540", + "VendorIDs": [ + "GO-2023-1752" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24540", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d6487f952d4539c2b86f155b5e4fbc94f6da34f8ae12ff88767fa50325ac1f6f", + "Title": "golang: html/template: improper handling of JavaScript whitespace", + "Description": "Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set \"\\t\\n\\f\\r\\u0020\\u2028\\u2029\" in JavaScript contexts that also contain actions may not be properly sanitized during execution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-77" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24540", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/4a28cad66655ee01c6e944271e23c33cab021765%20%28go1.20.4%29", + "https://github.com/golang/go/commit/ce7bd33345416e6d8cac901792060591cafc2797%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59721", + "https://go.dev/cl/491616", + "https://go.dev/issue/59721", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-24540.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24540", + "https://pkg.go.dev/vuln/GO-2023-1752", + "https://security.netapp.com/advisory/ntap-20241115-0008/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24540" + ], + "PublishedDate": "2023-05-11T16:15:09.687Z", + "LastModifiedDate": "2026-06-17T05:39:30.007Z" + }, + { + "VulnerabilityID": "CVE-2024-24790", + "VendorIDs": [ + "GO-2024-2887" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.21.11, 1.22.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-24790", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:cdcaf6066765a16afaea7db273980ea33f90c164fe3f72925e272fe3d0ef8272", + "Title": "golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses", + "Description": "The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.", + "Severity": "CRITICAL", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "bottlerocket": 2, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.7 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "http://www.openwall.com/lists/oss-security/2024/06/04/1", + "https://access.redhat.com/errata/RHSA-2025:7256", + "https://access.redhat.com/security/cve/CVE-2024-24790", + "https://bugzilla.redhat.com/2237777", + "https://bugzilla.redhat.com/2237778", + "https://bugzilla.redhat.com/2279814", + "https://bugzilla.redhat.com/2292787", + "https://bugzilla.redhat.com/2295310", + "https://bugzilla.redhat.com/2315719", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2279814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2292787", + "https://bugzilla.redhat.com/show_bug.cgi?id=2295310", + "https://bugzilla.redhat.com/show_bug.cgi?id=2315719", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24788", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24791", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9355", + "https://errata.almalinux.org/9/ALSA-2025-7256.html", + "https://errata.rockylinux.org/RLSA-2025:7256", + "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/2.9.0/BRSA-glvb5gspjgq6.toml", + "https://github.com/golang/go/commit/051bdf3fd12a40307606ff9381138039c5f452f0%20%281.21%29", + "https://github.com/golang/go/commit/12d5810cdb1f73cf23d7a86462143e9463317fca%20%281.22%29", + "https://github.com/golang/go/issues/67680", + "https://go.dev/cl/590316", + "https://go.dev/issue/67680", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ", + "https://linux.oracle.com/cve/CVE-2024-24790.html", + "https://linux.oracle.com/errata/ELSA-2025-7256.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-24790", + "https://pkg.go.dev/vuln/GO-2024-2887", + "https://security.netapp.com/advisory/ntap-20240905-0002/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2024-24790" + ], + "PublishedDate": "2024-06-05T16:15:10.56Z", + "LastModifiedDate": "2026-06-17T07:14:52.097Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a265fc11db8e3b0160df07ac5e4721e2180f968c3302e7c1e515fb3ddd152d0d", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2022-27664", + "VendorIDs": [ + "GHSA-69cg-p879-7622", + "GO-2022-0969" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.18.6, 1.19.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-27664", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6cad9b728bb24cfc4e32e9ae0d22cf6bab1622f0bcc5aba7b2543805343ddbea", + "Title": "golang: net/http: handle server errors after sending GOAWAY", + "Description": "In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:2177", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-27664", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2124669", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27664", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2023:2177", + "https://github.com/golang/go/commit/5bc9106458fc07851ac324a4157132a91b1f3479%20%28go1.18.6%29", + "https://github.com/golang/go/commit/9cfe4e258b1c9d4a04a42539c21c7bdb2e227824%20%28go1.19.1%29", + "https://github.com/golang/go/issues/54658", + "https://go.dev/cl/428735", + "https://go.dev/issue/54658", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s", + "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s/m/0tgO0pjiBQAJ", + "https://linux.oracle.com/cve/CVE-2022-27664.html", + "https://linux.oracle.com/errata/ELSA-2024-0121.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-27664", + "https://pkg.go.dev/vuln/GO-2022-0969", + "https://security.gentoo.org/glsa/202209-26", + "https://security.netapp.com/advisory/ntap-20220923-0004/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-8089-1", + "https://ubuntu.com/security/notices/USN-8089-2", + "https://ubuntu.com/security/notices/USN-8089-3", + "https://www.cve.org/CVERecord?id=CVE-2022-27664" + ], + "PublishedDate": "2022-09-06T18:15:12.747Z", + "LastModifiedDate": "2026-06-17T04:37:26.873Z" + }, + { + "VulnerabilityID": "CVE-2022-2879", + "VendorIDs": [ + "GO-2022-1037" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-2879", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:19752bcb14106889288cdc3bfef660883c1d538d8779b8d64e71d53977cdd477", + "Title": "golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers", + "Description": "Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2204", + "https://access.redhat.com/security/cve/CVE-2022-2879", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132867", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2204.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/0a723816cd205576945fa57fbdde7e6532d59d08%20%28go1.18.7%29", + "https://github.com/golang/go/commit/4fa773cdefd20be093c84f731be7d4febf5536fa%20%28go1.19.2%29", + "https://github.com/golang/go/issues/54853", + "https://github.com/vbatts/tar-split/releases/tag/v0.12.1", + "https://go.dev/cl/439355", + "https://go.dev/issue/54853", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-2879.html", + "https://linux.oracle.com/errata/ELSA-2024-2988.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-2879", + "https://pkg.go.dev/vuln/GO-2022-1037", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-2879" + ], + "PublishedDate": "2022-10-14T15:15:17.647Z", + "LastModifiedDate": "2026-06-17T04:42:45.443Z" + }, + { + "VulnerabilityID": "CVE-2022-2880", + "VendorIDs": [ + "GO-2022-1038" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-2880", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4e127f6d68e28d89c7f99ab751fe8eff3de1def6db2b59a449c113ca18d003bf", + "Title": "golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters", + "Description": "Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-444" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-2880", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/9d2c73a9fd69e45876509bb3bdb2af99bf77da1e%20%28go1.18.7%29", + "https://github.com/golang/go/commit/f6d844510d5f1e3b3098eba255d9b633d45eac3b%20%28go1.19.2%29", + "https://github.com/golang/go/issues/54663", + "https://go.dev/cl/432976", + "https://go.dev/issue/54663", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-2880.html", + "https://linux.oracle.com/errata/ELSA-2024-3254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-2880", + "https://pkg.go.dev/vuln/GO-2022-1038", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-2880" + ], + "PublishedDate": "2022-10-14T15:15:18.09Z", + "LastModifiedDate": "2026-06-17T04:42:45.547Z" + }, + { + "VulnerabilityID": "CVE-2022-41715", + "VendorIDs": [ + "GO-2022-1039" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41715", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e307d0970da0c8ee6f39b73bf33ad5c0d515658ca8c98e1e4edc49d25a6bc342", + "Title": "golang: regexp/syntax: limit memory used by parsing regexps", + "Description": "Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2592", + "https://access.redhat.com/security/cve/CVE-2022-41715", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2592.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/645abfe529dc325e16daa17210640c2907d1c17a%20%28go1.19.2%29", + "https://github.com/golang/go/commit/e9017c2416ad0ef642f5e0c2eab2dbf3cba4d997%20%28go1.18.7%29", + "https://github.com/golang/go/issues/55949", + "https://go.dev/cl/439356", + "https://go.dev/issue/55949", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-41715.html", + "https://linux.oracle.com/errata/ELSA-2024-3254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41715", + "https://pkg.go.dev/vuln/GO-2022-1039", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41715" + ], + "PublishedDate": "2022-10-14T15:16:20.78Z", + "LastModifiedDate": "2026-06-17T05:03:41.893Z" + }, + { + "VulnerabilityID": "CVE-2022-41716", + "VendorIDs": [ + "GO-2022-1095" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.18.8, 1.19.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41716", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e1ad84c84f30aabd2eb2544ff5b648878190f767e389c03057a73ea93760cf62", + "Title": "Due to unsanitized NUL values, attackers may be able to maliciously se ...", + "Description": "Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string \"A=B\\x00C=D\" sets the variables \"A=B\" and \"C=D\".", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/446916", + "https://go.dev/issue/56284", + "https://groups.google.com/g/golang-announce/c/mbHY1UY3BaM/m/hSpmRzk-AgAJ", + "https://linux.oracle.com/cve/CVE-2022-41716.html", + "https://linux.oracle.com/errata/ELSA-2023-18908.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41716", + "https://pkg.go.dev/vuln/GO-2022-1095", + "https://security.netapp.com/advisory/ntap-20230120-0007/" + ], + "PublishedDate": "2022-11-02T16:15:11.15Z", + "LastModifiedDate": "2026-06-17T05:03:41.997Z" + }, + { + "VulnerabilityID": "CVE-2022-41720", + "VendorIDs": [ + "GO-2022-1143" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.18.9, 1.19.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41720", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6355c595e31a10702beb71777a411cf58f7bf39f8a495b44b811308487055d22", + "Title": "golang: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows", + "Description": "On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS(\"C:/tmp\").Open(\"COM1\") opens the COM1 device. Both os.DirFS and http.Dir only provide read-only filesystem access. In addition, on Windows, an os.DirFS for the directory (the root of the current drive) can permit a maliciously crafted path to escape from the drive and access any path on the system. With fix applied, the behavior of os.DirFS(\"\") has changed. Previously, an empty root was treated equivalently to \"/\", so os.DirFS(\"\").Open(\"tmp\") would open the path \"/tmp\". This now returns an error.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-41720", + "https://go.dev/cl/455716", + "https://go.dev/issue/56694", + "https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ", + "https://linux.oracle.com/cve/CVE-2022-41720.html", + "https://linux.oracle.com/errata/ELSA-2023-18908.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41720", + "https://pkg.go.dev/vuln/GO-2022-1143", + "https://www.cve.org/CVERecord?id=CVE-2022-41720" + ], + "PublishedDate": "2022-12-07T17:15:10.293Z", + "LastModifiedDate": "2026-06-17T05:03:42.497Z" + }, + { + "VulnerabilityID": "CVE-2022-41722", + "VendorIDs": [ + "GO-2023-1568" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41722", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3f30dea7b43ff75e8807aad86271c930310208eda84a3d6d1b743f33663b09bc", + "Title": "golang: path/filepath: path-filepath filepath.Clean path traversal", + "Description": "A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as \"a/../c:/b\" into the valid path \"c:\\b\". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path \".\\c:\\b\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-41722", + "https://go.dev/cl/468123", + "https://go.dev/issue/57274", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41722", + "https://pkg.go.dev/vuln/GO-2023-1568", + "https://www.cve.org/CVERecord?id=CVE-2022-41722" + ], + "PublishedDate": "2023-02-28T18:15:09.887Z", + "LastModifiedDate": "2026-06-17T05:03:42.79Z" + }, + { + "VulnerabilityID": "CVE-2022-41723", + "VendorIDs": [ + "GHSA-vvpx-j8f3-3w6h", + "GO-2023-1571" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41723", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b94668e5bc28b282f9583cd70b899fa2a78a50724bc3112cc6562b838e5fceed", + "Title": "golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding", + "Description": "A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41723", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/advisories/GHSA-vvpx-j8f3-3w6h", + "https://go.dev/cl/468135", + "https://go.dev/cl/468295", + "https://go.dev/issue/57855", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41723.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MA5XS5DAOJ5PKKNG5TUXKPQOFHT5VBC/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGW7GE2Z32ZT47UFAQFDRQE33B7Q7LMT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41723", + "https://pkg.go.dev/vuln/GO-2023-1571", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230331-0010/", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://ubuntu.com/security/notices/USN-8089-1", + "https://ubuntu.com/security/notices/USN-8089-2", + "https://ubuntu.com/security/notices/USN-8089-3", + "https://vuln.go.dev/ID/GO-2023-1571.json", + "https://www.couchbase.com/alerts/", + "https://www.cve.org/CVERecord?id=CVE-2022-41723" + ], + "PublishedDate": "2023-02-28T18:15:09.98Z", + "LastModifiedDate": "2026-06-17T05:03:42.9Z" + }, + { + "VulnerabilityID": "CVE-2022-41724", + "VendorIDs": [ + "GO-2023-1570" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41724", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a3fc00cfe07c714ac41bccb546356e484b599a0527e2e3e47688100043fece20", + "Title": "golang: crypto/tls: large handshake records may cause panics", + "Description": "Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41724", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://go.dev/cl/468125", + "https://go.dev/issue/58001", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41724.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41724", + "https://pkg.go.dev/vuln/GO-2023-1570", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41724" + ], + "PublishedDate": "2023-02-28T18:15:10.043Z", + "LastModifiedDate": "2026-06-17T05:03:43.11Z" + }, + { + "VulnerabilityID": "CVE-2022-41725", + "VendorIDs": [ + "GO-2023-1569" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41725", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:806d5f2a8b5b24f733e95ccc0996069e16050524735118f2a0665b8d32779015", + "Title": "golang: net/http, mime/multipart: denial of service from excessive resource consumption", + "Description": "A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing \"up to maxMemory bytes +10MB (reserved for non-file parts) in memory\". File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did not properly account for all memory consumed by a parsed form, such as map entry overhead, part names, and MIME headers, permitting a maliciously crafted form to consume well over 10MB. In addition, ReadForm contained no limit on the number of disk files created, permitting a relatively small request body to create a large number of disk temporary files. With fix, ReadForm now properly accounts for various forms of memory overhead, and should now stay within its documented limit of 10MB + maxMemory bytes of memory consumption. Users should still be aware that this limit is high and may still be hazardous. In addition, ReadForm now creates at most one on-disk temporary file, combining multiple form parts into a single temporary file. The mime/multipart.File interface type's documentation states, \"If stored on disk, the File's underlying concrete type will be an *os.File.\". This is no longer the case when a form contains more than one file part, due to this coalescing of parts into a single file. The previous behavior of using distinct files for each form part may be reenabled with the environment variable GODEBUG=multipartfiles=distinct. Users should be aware that multipart.ReadForm and the http.Request methods that call it do not limit the amount of disk consumed by temporary files. Callers can limit the size of form data with http.MaxBytesReader.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41725", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/5c55ac9bf1e5f779220294c843526536605f42ab%20%5B1.19%5D", + "https://go.dev/cl/468124", + "https://go.dev/issue/58006", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41725.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41725", + "https://pkg.go.dev/vuln/GO-2023-1569", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41725" + ], + "PublishedDate": "2023-02-28T18:15:10.12Z", + "LastModifiedDate": "2026-06-17T05:03:43.243Z" + }, + { + "VulnerabilityID": "CVE-2023-24534", + "VendorIDs": [ + "GO-2023-1704" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24534", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1089cbd104cdbeb4e921c0302660f62f9f433835ba0e701e7eb988cd99a31448", + "Title": "golang: net/http, net/textproto: denial of service from excessive memory allocation", + "Description": "HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more memory than required to hold the parsed headers. An attacker can exploit this behavior to cause an HTTP server to allocate large amounts of memory from a small request, potentially leading to memory exhaustion and a denial of service. With fix, header parsing now correctly allocates only the memory required to hold parsed headers.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24534", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/3991f6c41c7dfd167e889234c0cf1d840475e93c%20%28go1.20.3%29", + "https://github.com/golang/go/commit/d6759e7a059f4208f07aa781402841d7ddaaef96%20%28go1.19.8%29", + "https://go.dev/cl/481994", + "https://go.dev/issue/58975", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24534.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24534", + "https://pkg.go.dev/vuln/GO-2023-1704", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230526-0007/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24534" + ], + "PublishedDate": "2023-04-06T16:15:07.657Z", + "LastModifiedDate": "2026-06-17T05:39:28.893Z" + }, + { + "VulnerabilityID": "CVE-2023-24536", + "VendorIDs": [ + "GO-2023-1705" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24536", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3c4db5e03750ac6dea95d558486b6ca1aae3b803ef78074df651ffefc6b0d28e", + "Title": "golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption", + "Description": "Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems from several causes: 1. mime/multipart.Reader.ReadForm limits the total memory a parsed multipart form can consume. ReadForm can undercount the amount of memory consumed, leading it to accept larger inputs than intended. 2. Limiting total memory does not account for increased pressure on the garbage collector from large numbers of small allocations in forms with many parts. 3. ReadForm can allocate a large number of short-lived buffers, further increasing pressure on the garbage collector. The combination of these factors can permit an attacker to cause an program that parses multipart forms to consume large amounts of CPU and memory, potentially resulting in a denial of service. This affects programs that use mime/multipart.Reader.ReadForm, as well as form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. With fix, ReadForm now does a better job of estimating the memory consumption of parsed forms, and performs many fewer short-lived allocations. In addition, the fixed mime/multipart.Reader imposes the following limits on the size of parsed forms: 1. Forms parsed with ReadForm may contain no more than 1000 parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxparts=. 2. Form parts parsed with NextPart and NextRawPart may contain no more than 10,000 header fields. In addition, forms parsed with ReadForm may contain no more than 10,000 header fields across all parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxheaders=.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24536", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/7917b5f31204528ea72e0629f0b7d52b35b27538%20%28go.1.19.8%29", + "https://github.com/golang/go/commit/bf8c7c575c8a552d9d79deb29e80854dc88528d0%20%28go1.20.3%29", + "https://go.dev/cl/482075", + "https://go.dev/cl/482076", + "https://go.dev/cl/482077", + "https://go.dev/issue/59153", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24536.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24536", + "https://pkg.go.dev/vuln/GO-2023-1705", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230526-0007/", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24536" + ], + "PublishedDate": "2023-04-06T16:15:07.71Z", + "LastModifiedDate": "2026-06-17T05:39:29.287Z" + }, + { + "VulnerabilityID": "CVE-2023-24537", + "VendorIDs": [ + "GO-2023-1702" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24537", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c5a5524922c669b5f605a461ef884b4a0ecf1c665420c4368354473daeac535d", + "Title": "golang: go/parser: Infinite loop in parsing", + "Description": "Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24537", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/126a1d02da82f93ede7ce0bd8d3c51ef627f2104%20%28go1.19.8%29", + "https://github.com/golang/go/commit/e7c4b07ecf6b367f1afc9cc48cde963829dd0aab%20%28go1.20.3%29", + "https://github.com/golang/go/issues/59180", + "https://go.dev/cl/482078", + "https://go.dev/issue/59180", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24537.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24537", + "https://pkg.go.dev/vuln/GO-2023-1702", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241129-0004/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24537" + ], + "PublishedDate": "2023-04-06T16:15:07.753Z", + "LastModifiedDate": "2026-06-17T05:39:29.483Z" + }, + { + "VulnerabilityID": "CVE-2023-24539", + "VendorIDs": [ + "GO-2023-1751" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24539", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:54afb7ff7b71cd1cfe06ba7e894a629b1b1926c346c97d240f100aedce41c93b", + "Title": "golang: html/template: improper sanitization of CSS values", + "Description": "Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24539", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/090590fdccc8442728aa31601927da1bf2ef1288%20%28go1.20.4%29", + "https://github.com/golang/go/commit/e49282327b05192e46086bf25fd3ac691205fe80%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59720", + "https://go.dev/cl/491615", + "https://go.dev/issue/59720", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-24539.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24539", + "https://pkg.go.dev/vuln/GO-2023-1751", + "https://security.netapp.com/advisory/ntap-20241129-0005/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24539" + ], + "PublishedDate": "2023-05-11T16:15:09.6Z", + "LastModifiedDate": "2026-06-17T05:39:29.84Z" + }, + { + "VulnerabilityID": "CVE-2023-29400", + "VendorIDs": [ + "GO-2023-1753" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-29400", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:51ff30725338375f352c79e4c34b6aefcec06e2b12ed4e406d9ec83d4cfdb940", + "Title": "golang: html/template: improper handling of empty HTML attributes", + "Description": "Templates containing actions in unquoted HTML attributes (e.g. \"attr={{.}}\") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-29400", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/337dd75343145b74ed2073d793322eb4103b56ad%20%28go1.20.4%29", + "https://github.com/golang/go/commit/9db0e74f606b8afb28cc71d4b1c8b4ed24cabbf5%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59722", + "https://go.dev/cl/491617", + "https://go.dev/issue/59722", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-29400.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-29400", + "https://pkg.go.dev/vuln/GO-2023-1753", + "https://security.netapp.com/advisory/ntap-20241213-0005/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-29400" + ], + "PublishedDate": "2023-05-11T16:15:09.85Z", + "LastModifiedDate": "2026-06-17T05:49:57.937Z" + }, + { + "VulnerabilityID": "CVE-2023-29403", + "VendorIDs": [ + "GO-2023-1840" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.19.10, 1.20.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-29403", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c1dab1ec9ab5dc7e92190e1c64854d59fd8514451417bd4a271b230d8bbb800c", + "Title": "golang: runtime: unexpected behavior of setuid/setgid binaries", + "Description": "On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-668" + ], + "VendorSeverity": { + "alma": 4, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 4, + "photon": 3, + "redhat": 3, + "rocky": 4, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:3923", + "https://access.redhat.com/security/cve/CVE-2023-29403", + "https://bugzilla.redhat.com/2216965", + "https://bugzilla.redhat.com/2217562", + "https://bugzilla.redhat.com/2217565", + "https://bugzilla.redhat.com/2217569", + "https://bugzilla.redhat.com/show_bug.cgi?id=2216965", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217562", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217565", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217569", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29402", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29403", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29404", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29405", + "https://errata.almalinux.org/9/ALSA-2023-3923.html", + "https://errata.rockylinux.org/RLSA-2023:3923", + "https://github.com/golang/go/commit/36144ba429ef2650940c72e7a0b932af3612d420%20%28go1.20.5%29", + "https://github.com/golang/go/commit/a7b1cd452ddc69a6606c2f35ac5786dc892e62cb%20%28go1.19.10%29", + "https://github.com/golang/go/issues/60272", + "https://go.dev/cl/501223", + "https://go.dev/issue/60272", + "https://groups.google.com/g/golang-announce/c/q5135a9d924", + "https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJ", + "https://linux.oracle.com/cve/CVE-2023-29403.html", + "https://linux.oracle.com/errata/ELSA-2023-3923.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZ2O6YCO2IZMZJELQGZYR2WAUNEDLYV6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XBS3IIK6ADV24C5ULQU55QLT2UE762ZX/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-29403", + "https://pkg.go.dev/vuln/GO-2023-1840", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241220-0009/", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2023-29403" + ], + "PublishedDate": "2023-06-08T21:15:16.927Z", + "LastModifiedDate": "2026-06-17T05:49:58.43Z" + }, + { + "VulnerabilityID": "CVE-2023-39325", + "VendorIDs": [ + "GHSA-4374-p667-p6c8", + "GO-2023-2102" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.20.10, 1.21.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-39325", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:928aef4884dc01f801214c7a18ce512d542c23b91c4564ee46da9c28eb39b91a", + "Title": "golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)", + "Description": "A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "bottlerocket": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39325", + "https://access.redhat.com/errata/RHSA-2023:6077", + "https://access.redhat.com/security/cve/CVE-2023-39325", + "https://access.redhat.com/security/cve/CVE-2023-44487", + "https://bugzilla.redhat.com/2242803", + "https://bugzilla.redhat.com/2243296", + "https://bugzilla.redhat.com/show_bug.cgi?id=2242803", + "https://bugzilla.redhat.com/show_bug.cgi?id=2243296", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39325", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44487", + "https://errata.almalinux.org/9/ALSA-2023-6077.html", + "https://errata.rockylinux.org/RLSA-2023:6077", + "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-48vh-q3rp-4grw", + "https://github.com/golang/go/commit/24ae2d927285c697440fdde3ad7f26028354bcf3%20%5Bgolang-%201.21%5D", + "https://github.com/golang/go/commit/e175f27f58aa7b9cd4d79607ae65d2cd5baaee68%20%5Bgolang-1.20%5D", + "https://github.com/golang/go/issues/63417", + "https://go.dev/cl/534215", + "https://go.dev/cl/534235", + "https://go.dev/issue/63417", + "https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ", + "https://linux.oracle.com/cve/CVE-2023-39325.html", + "https://linux.oracle.com/errata/ELSA-2023-5867.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3OVW5V2DM5K5IC3H7O42YDUGNJ74J35O/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3SZN67IL7HMGMNAVLOTIXLIHUDXZK4LH/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WJ4QVX2AMUJ2F2S27POOAHRC4K3CHU4/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5RSKA2II6QTD4YUKUNDVJQSRYSFC4VFR/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVZDNSMVDAQJ64LJC5I5U5LDM5753647/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2BBIDR2ZMB3X5BC7SR4SLQMHRMVPY6L/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECRC75BQJP6FJN2L7KCKYZW4DSBD7QSD/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FTMJ3NJIDAZFWJQQSP3L22MUFJ3UP2PT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSY7SXFFTPZFWDM6XELSDSHZLVW3AHK7/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HZQIELEIRSZUYTFFH5KTH2YJ4IIQG2KE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPWCNYB5PQ5PCVZ4NJT6G56ZYFZ5QBU6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5E5JSJBZLYXOTZWXHJKRVCIXIHVWKJ6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZQYOOKHQDQ57LV2IAG6NRFOVXKHJJ3Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NG7IMPL55MVWU3LCI4JQJT3K2U5CHDV7/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ODBY7RVMGZCBSTWF2OZGIZS57FNFUL67/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXGWPQOJ3JNDW2XIYKIVJ7N7QUIFNM2Q/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PJCUNGIQDUMZ4Z6HWVYIMR66A35F5S74/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QF5QSYAOPDOWLY6DUHID56Q4HQFYB45I/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXOU2JZUBEBP7GBKAYIJRPRBZSJCD7ST/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3UETKPUB3V5JS5TLZOF3SMTGT5K5APS/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULQQONMSCQSH5Z5OWFFQHCGEZ3NL4DRJ/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTT7DG3QOF5ZNJLUGHDNLRUIN6OWZARP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2LZSWTV4NV4SNQARNXG5T6LRHP26EW2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WCNCBYKZXLDFGAJUB7ZP5VLC3YTHJNVH/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XTNLSL44Y5FB6JWADSZH6DCV4JJAAEQY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJWHBLVZDM5KQSDFRBFRKU5KSSOLIRQ4/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRKEXKANQ7BKJW2YTAMP625LJUJZLJ4P/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZSVEMQV5ROY5YW5QE3I57HT3ITWG5GCV/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-39325", + "https://pkg.go.dev/vuln/GO-2023-2102", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20231110-0008/", + "https://ubuntu.com/security/notices/USN-6574-1", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487", + "https://www.cve.org/CVERecord?id=CVE-2023-39325" + ], + "PublishedDate": "2023-10-11T22:15:09.88Z", + "LastModifiedDate": "2026-06-17T06:12:02.173Z" + }, + { + "VulnerabilityID": "CVE-2023-45283", + "VendorIDs": [ + "GO-2023-2185" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.20.11, 1.21.4, 1.20.12, 1.21.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:fdac34ec3b15f3a3dcb0ffddc18b3c84fc8bc499eb9c8869d8b4a598649072c2", + "Title": "The filepath package does not recognize paths with a \\??\\ prefix as sp ...", + "Description": "The filepath package does not recognize paths with a \\??\\ prefix as special. On Windows, a path beginning with \\??\\ is a Root Local Device path equivalent to a path beginning with \\\\?\\. Paths with a \\??\\ prefix may be used to access arbitrary locations on the system. For example, the path \\??\\c:\\x is equivalent to the more common path c:\\x. Before fix, Clean could convert a rooted path such as \\a\\..\\??\\b into the root local device path \\??\\b. Clean will now convert this to .\\??\\b. Similarly, Join(\\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \\??\\b. Join will now convert this to \\.\\??\\b. In addition, with fix, IsAbs now correctly reports paths beginning with \\??\\ as absolute, and VolumeName correctly reports the \\??\\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \\?, resulting in filepath.Clean(\\?\\c:) returning \\?\\c: rather than \\?\\c:\\ (among other effects). The previous behavior has been restored.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "amazon": 2, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2023/12/05/2", + "https://go.dev/cl/540277", + "https://go.dev/cl/541175", + "https://go.dev/issue/63713", + "https://go.dev/issue/64028", + "https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY", + "https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45283", + "https://pkg.go.dev/vuln/GO-2023-2185", + "https://security.netapp.com/advisory/ntap-20231214-0008/" + ], + "PublishedDate": "2023-11-09T17:15:08.757Z", + "LastModifiedDate": "2026-06-17T06:28:34.863Z" + }, + { + "VulnerabilityID": "CVE-2023-45287", + "VendorIDs": [ + "GO-2023-2375" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.20.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45287", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ce9696ba6190164b200b3e9d5ac4962adfc047ef93db1e42486fdbb90687082d", + "Title": "golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.", + "Description": "Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-203" + ], + "VendorSeverity": { + "alma": 2, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:2272", + "https://access.redhat.com/errata/RHSA-2024:2988", + "https://access.redhat.com/security/cve/CVE-2023-45287", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/2253330", + "https://bugzilla.redhat.com/show_bug.cgi?id=1983596", + "https://bugzilla.redhat.com/show_bug.cgi?id=1989575", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237773", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237776", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2244340", + "https://bugzilla.redhat.com/show_bug.cgi?id=2246840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2253330", + "https://bugzilla.redhat.com/show_bug.cgi?id=2254210", + "https://bugzilla.redhat.com/show_bug.cgi?id=2262272", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25091", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33198", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29409", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39318", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39319", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39326", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45287", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23650", + "https://errata.almalinux.org/9/ALSA-2024-2272.html", + "https://errata.rockylinux.org/RLSA-2024:2988", + "https://go.dev/cl/326012/26", + "https://go.dev/issue/20654", + "https://groups.google.com/g/golang-announce/c/QMK8IQALDvA", + "https://linux.oracle.com/cve/CVE-2023-45287.html", + "https://linux.oracle.com/errata/ELSA-2024-2988.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45287", + "https://people.redhat.com/~hkario/marvin/", + "https://pkg.go.dev/vuln/GO-2023-2375", + "https://security.netapp.com/advisory/ntap-20240112-0005/", + "https://www.cve.org/CVERecord?id=CVE-2023-45287" + ], + "PublishedDate": "2023-12-05T17:15:08.57Z", + "LastModifiedDate": "2026-06-17T06:28:35.46Z" + }, + { + "VulnerabilityID": "CVE-2023-45288", + "VendorIDs": [ + "GHSA-4v7x-pqxf-cx7m", + "GO-2024-2687" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.21.9, 1.22.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45288", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:43535ab737d075499d722ccf88350ba54629eebfab80e3edb444ef1d14b8e46b", + "Title": "golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS", + "Description": "An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "bottlerocket": 2, + "cbl-mariner": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288", + "http://www.openwall.com/lists/oss-security/2024/04/03/16", + "http://www.openwall.com/lists/oss-security/2024/04/05/4", + "https://access.redhat.com/errata/RHSA-2024:2724", + "https://access.redhat.com/security/cve/CVE-2023-45288", + "https://bugzilla.redhat.com/2268017", + "https://bugzilla.redhat.com/2268018", + "https://bugzilla.redhat.com/2268019", + "https://bugzilla.redhat.com/2268273", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268017", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268018", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268019", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268273", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45289", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45290", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24783", + "https://errata.almalinux.org/9/ALSA-2024-2724.html", + "https://errata.rockylinux.org/RLSA-2024:2724", + "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-c9wf-j9h6-m2r9", + "https://go.dev/cl/576155", + "https://go.dev/issue/65051", + "https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M", + "https://kb.cert.org/vuls/id/421644", + "https://linux.oracle.com/cve/CVE-2023-45288.html", + "https://linux.oracle.com/errata/ELSA-2024-3346.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRYFHIQ6XRKRYBI2F5UESH67BJBQXUPT/", + "https://nowotarski.info/http2-continuation-flood/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45288", + "https://pkg.go.dev/vuln/GO-2024-2687", + "https://security.netapp.com/advisory/ntap-20240419-0009/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2023-45288", + "https://www.kb.cert.org/vuls/id/421644" + ], + "PublishedDate": "2024-04-04T21:15:16.113Z", + "LastModifiedDate": "2026-06-17T06:28:35.58Z" + }, + { + "VulnerabilityID": "CVE-2024-34156", + "VendorIDs": [ + "GO-2024-3106" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.22.7, 1.23.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-34156", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:60053a8bd2f005a632f95c5df4c5980d4f6364e71e0145c7d8c97a5c04e54650", + "Title": "encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion", + "Description": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:3773", + "https://access.redhat.com/security/cve/CVE-2024-34156", + "https://bugzilla.redhat.com/2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341750", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341751", + "https://bugzilla.redhat.com/show_bug.cgi?id=2344219", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866", + "https://errata.almalinux.org/9/ALSA-2025-3773.html", + "https://errata.rockylinux.org/RLSA-2025:3773", + "https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01%20%28go1.22.7%29", + "https://github.com/golang/go/commit/fa8ff1a46deb6c816304441ec6740ec112e19012%20%28go1.23.1%29", + "https://go.dev/cl/611239", + "https://go.dev/issue/69139", + "https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc", + "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk", + "https://linux.oracle.com/cve/CVE-2024-34156.html", + "https://linux.oracle.com/errata/ELSA-2025-3773.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-34156", + "https://pkg.go.dev/vuln/GO-2024-3106", + "https://security.netapp.com/advisory/ntap-20240926-0004/", + "https://ubuntu.com/security/notices/USN-7081-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2024-34156" + ], + "PublishedDate": "2024-09-06T21:15:12.02Z", + "LastModifiedDate": "2026-06-17T07:33:00.72Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:14ce1061b88ddf750c0c39d4baadd75ee1ab0c3cca1b4d679a6da2945975adfd", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-08-14T13:17:15.67Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5954f9bc767e87cf6088f0a057e26177e062c421907e5b2a8ed2fccc7a6fc0bb", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ef0ee426f5eeb6ee62235eac3f146f71ef04446683b42e694d3986727266ae02", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-08-14T13:17:46.517Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7207c64ced9889e6f72182b901bf0a6fa86fbf6e2777d8add71ecc541fb2bf33", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-08-14T13:17:49.537Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:73968abe9fcc6b04c7cff947d93ba5b77619432755b8b42fa5b278d49fdf1094", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-08-14T13:17:52.587Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:41712d6990dae112752772639ff140e9335d590e9a71b7ee97d0e7fa7ddebbce", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d2e1fa326ee31dbf373e77cc4dd8a344ab6a7a8943ba63881dc0d9bfdae55cac", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-33722.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-08-14T13:17:54.66Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b60418f80f9a9bc3ea4d8cb3536d0a2ba48e00f5367694fa0a34547ae7c90c4f", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:39319", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-39573.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-08-14T13:18:12Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:aae2676d659e795021e1eb7eea73cd52f8caa2d991f96ce6f0a506de21858da6", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-08-13T13:18:25.52Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f7e740c0664f038ca4b81a76ed4e6a8bd4615497fc02e8a4e1b994ea9d9b2b27", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-08-14T16:16:55.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a7a085148ca4bc30a179e792c14a75030cd80b9dd98b43b7e6a852d2578b291f", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-08-14T13:18:23.657Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1837a5b5f82019779efb2d8ab86c18fbd93a1e739c72f045408c2454cb50bb7e", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:37435", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-08-14T13:18:24.667Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:82583641976603d9a99eb48b2c92c8162afadd667263b925cc2c579685441542", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4a6a2cad21c9c2c2905715d05b8c57530b17b68eca30b030dd9e1f5fb8fc3259", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c1c8338432359bf8f553d373cd035434a38d0f4297874372cff1ae0f3091256d", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-08-14T13:18:47.497Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:083995d4a1423377ef6f5f2100809897638f0d265cdd2ced22c305f8d4aaebc1", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:159c7979b15a5b90af6c653bace6fea9e9ab3c259ece3989731b542509c365d2", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-08-14T16:16:57.21Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6395af333e3bb1b4721e643999e7d16e9756ed18789f09af0e3a3f421a3f93e0", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-08-14T16:16:57.367Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:bd170c15af49280ccafebad28afcf7d181eea34d96069b700fe5679a3e989dd8", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-08-14T16:16:57.523Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8935f4af676d1bbb304a5cfdc86d778622f15f846e455cb5e2eb08c00c3810ff", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-08-14T17:19:13.91Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.18.5", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.18.5", + "UID": "812b64c03de3f4f5" + }, + "InstalledVersion": "v1.18.5", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:561c0852c9602be13ca7c597cf18710d99854fb897d847c81c50eb328ddd04bc", + "DiffID": "sha256:0ae53b2fc3838c1eec60d45df153f9e2ad3a6ea7c4c35acb5ad5a854c6d95b8c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:55b1664586a3362b0790bac4cc9193bf47a5edfa08ce63f0e500fedd5f4810ae", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-08-14T16:16:57.717Z" + } + ], + "vulnerability_count": 172 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 172 + } +} diff --git a/bfx/igv/trivy-scan-results.json b/bfx/igv/trivy-scan-results.json new file mode 100644 index 00000000..c647675b --- /dev/null +++ b/bfx/igv/trivy-scan-results.json @@ -0,0 +1,769 @@ +{ + "tool": "igv", + "scan_timestamp": "2026-08-16T17:07:57Z", + "workflow_run_id": "31960542324", + "versions": { + "2.19.8": { + "image": "ghcr.io/bundlecore/products/bfx/igv:2.19.8", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-42583", + "VendorIDs": [ + "GHSA-mj4r-2hfc-f8p6" + ], + "PkgName": "io.netty:netty-codec", + "PkgPath": "usr/local/lib/igv/netty-codec-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-codec@4.1.118.Final", + "UID": "562c6b56f351274" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.1.133.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42583", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:f510052aeb978a02cd7599619cbaddf90299255851360659015b1b73858b2d13", + "Title": "netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder", + "Description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42583", + "https://github.com/netty/netty", + "https://github.com/netty/netty/security/advisories/GHSA-mj4r-2hfc-f8p6", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42583", + "https://www.cve.org/CVERecord?id=CVE-2026-42583" + ], + "PublishedDate": "2026-05-13T19:17:23.903Z", + "LastModifiedDate": "2026-06-17T10:48:05.55Z" + }, + { + "VulnerabilityID": "CVE-2026-59901", + "VendorIDs": [ + "GHSA-558v-64gr-wgg4" + ], + "PkgName": "io.netty:netty-codec", + "PkgPath": "usr/local/lib/igv/netty-codec-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-codec@4.1.118.Final", + "UID": "562c6b56f351274" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.1.136.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59901", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:f0b9a3df5775ef6a84741f94dd38554bae0ef87fa4fe52c01ea32af787f13897", + "Title": "io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)", + "Description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59901", + "https://github.com/netty/netty", + "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final", + "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final", + "https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59901", + "https://www.cve.org/CVERecord?id=CVE-2026-59901" + ], + "PublishedDate": "2026-07-29T18:16:56.467Z", + "LastModifiedDate": "2026-08-06T20:29:27.587Z" + }, + { + "VulnerabilityID": "CVE-2026-33870", + "VendorIDs": [ + "GHSA-pwqr-wmgm-9rr8" + ], + "PkgName": "io.netty:netty-codec-http", + "PkgPath": "usr/local/lib/igv/netty-codec-http-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-codec-http@4.1.118.Final", + "UID": "5acb353df4c56cc3" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.1.132.Final, 4.2.10.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33870", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:33a2d243820a3217d76c38e884d495709a33d37e86b94586308ca885599a3858", + "Title": "io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values", + "Description": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-444" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14272", + "https://access.redhat.com/errata/RHSA-2026:14276", + "https://access.redhat.com/errata/RHSA-2026:17668", + "https://access.redhat.com/errata/RHSA-2026:17789", + "https://access.redhat.com/errata/RHSA-2026:18054", + "https://access.redhat.com/errata/RHSA-2026:18055", + "https://access.redhat.com/errata/RHSA-2026:18059", + "https://access.redhat.com/errata/RHSA-2026:22619", + "https://access.redhat.com/errata/RHSA-2026:34608", + "https://access.redhat.com/errata/RHSA-2026:7109", + "https://access.redhat.com/errata/RHSA-2026:7380", + "https://access.redhat.com/errata/RHSA-2026:8159", + "https://access.redhat.com/errata/RHSA-2026:8509", + "https://access.redhat.com/security/cve/CVE-2026-33870", + "https://bugzilla.redhat.com/show_bug.cgi?id=2452453", + "https://github.com/netty/netty", + "https://github.com/netty/netty/security/advisories/GHSA-pwqr-wmgm-9rr8", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33870.json", + "https://w4ke.info/2025/06/18/funky-chunks.html", + "https://w4ke.info/2025/10/29/funky-chunks-2.html", + "https://www.cve.org/CVERecord?id=CVE-2026-33870", + "https://www.rfc-editor.org/rfc/rfc9110" + ], + "PublishedDate": "2026-03-27T20:16:34.663Z", + "LastModifiedDate": "2026-08-04T13:18:20.043Z" + }, + { + "VulnerabilityID": "CVE-2026-42584", + "VendorIDs": [ + "GHSA-57rv-r2g8-2cj3" + ], + "PkgName": "io.netty:netty-codec-http", + "PkgPath": "usr/local/lib/igv/netty-codec-http-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-codec-http@4.1.118.Final", + "UID": "5acb353df4c56cc3" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.2.13.Final, 4.1.133.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42584", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:3fd7ec7f8e0c71d3d1a29b11259100f30e2aebad1a40e35f4ab69f36e2423515", + "Title": "netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion", + "Description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-444" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 4, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23808", + "https://access.redhat.com/errata/RHSA-2026:24502", + "https://access.redhat.com/errata/RHSA-2026:25123", + "https://access.redhat.com/errata/RHSA-2026:28010", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:37390", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:53644", + "https://access.redhat.com/errata/RHSA-2026:53806", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/security/cve/CVE-2026-42584", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477224", + "https://github.com/netty/netty", + "https://github.com/netty/netty/security/advisories/GHSA-57rv-r2g8-2cj3", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42584", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42584.json", + "https://ubuntu.com/security/notices/USN-8401-1", + "https://www.cve.org/CVERecord?id=CVE-2026-42584" + ], + "PublishedDate": "2026-05-13T19:17:24.043Z", + "LastModifiedDate": "2026-08-13T13:18:56.64Z" + }, + { + "VulnerabilityID": "CVE-2026-42587", + "VendorIDs": [ + "GHSA-f6hv-jmp6-3vwv" + ], + "PkgName": "io.netty:netty-codec-http", + "PkgPath": "usr/local/lib/igv/netty-codec-http-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-codec-http@4.1.118.Final", + "UID": "5acb353df4c56cc3" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.2.13.Final, 4.1.133.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42587", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:f31cf31209ee4509c80ffdb0b62cb286d4e5d6cc360a9b7cc62b00d77e49679c", + "Title": "netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression", + "Description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23808", + "https://access.redhat.com/errata/RHSA-2026:24502", + "https://access.redhat.com/errata/RHSA-2026:25123", + "https://access.redhat.com/errata/RHSA-2026:28010", + "https://access.redhat.com/errata/RHSA-2026:34608", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:37390", + "https://access.redhat.com/errata/RHSA-2026:41951", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:50085", + "https://access.redhat.com/errata/RHSA-2026:53644", + "https://access.redhat.com/errata/RHSA-2026:53806", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/security/cve/CVE-2026-42587", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477220", + "https://github.com/netty/netty", + "https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42587", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42587.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42587" + ], + "PublishedDate": "2026-05-13T19:17:24.46Z", + "LastModifiedDate": "2026-08-13T13:18:57.117Z" + }, + { + "VulnerabilityID": "CVE-2026-55831", + "VendorIDs": [ + "GHSA-6jqx-86gh-f27w" + ], + "PkgName": "io.netty:netty-codec-http", + "PkgPath": "usr/local/lib/igv/netty-codec-http-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-codec-http@4.1.118.Final", + "UID": "5acb353df4c56cc3" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.2.16.Final, 4.1.136.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55831", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:b3edcfa8eedf255c67fec5116d8e9b6442fc60c9e6b1c87514acd3da781b3eeb", + "Title": "io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing", + "Description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-55831", + "https://github.com/netty/netty", + "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b", + "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6", + "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final", + "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final", + "https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55831", + "https://www.cve.org/CVERecord?id=CVE-2026-55831" + ], + "PublishedDate": "2026-07-21T00:17:35.383Z", + "LastModifiedDate": "2026-07-23T15:17:16.78Z" + }, + { + "VulnerabilityID": "CVE-2026-55833", + "VendorIDs": [ + "GHSA-mvh2-crg5-v77c" + ], + "PkgName": "io.netty:netty-codec-http", + "PkgPath": "usr/local/lib/igv/netty-codec-http-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-codec-http@4.1.118.Final", + "UID": "5acb353df4c56cc3" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.2.16.Final, 4.1.136.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55833", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:65d8509caafc679cf3d31fecad4f1648b675970e756b3ad1a10fabc51a672cb6", + "Title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification", + "Description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-55833", + "https://github.com/netty/netty", + "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b", + "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6", + "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final", + "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final", + "https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55833", + "https://www.cve.org/CVERecord?id=CVE-2026-55833" + ], + "PublishedDate": "2026-07-21T00:17:35.537Z", + "LastModifiedDate": "2026-07-23T13:34:45.383Z" + }, + { + "VulnerabilityID": "CVE-2026-56745", + "VendorIDs": [ + "GHSA-jppx-w49h-x2qq" + ], + "PkgName": "io.netty:netty-codec-http", + "PkgPath": "usr/local/lib/igv/netty-codec-http-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-codec-http@4.1.118.Final", + "UID": "5acb353df4c56cc3" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.2.16.Final, 4.1.136.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56745", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:39cff0c12a283f1843a233dcdf4a6ce03c2dc60cbbfa53a150c5f7d8be42f39a", + "Title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec", + "Description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56745", + "https://github.com/netty/netty", + "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b", + "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6", + "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final", + "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final", + "https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56745", + "https://www.cve.org/CVERecord?id=CVE-2026-56745" + ], + "PublishedDate": "2026-07-21T22:17:14.5Z", + "LastModifiedDate": "2026-07-30T14:46:55.073Z" + }, + { + "VulnerabilityID": "CVE-2026-44249", + "VendorIDs": [ + "GHSA-3qp7-7mw8-wx86" + ], + "PkgName": "io.netty:netty-handler", + "PkgPath": "usr/local/lib/igv/netty-handler-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-handler@4.1.118.Final", + "UID": "312bbec760e08bac" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.2.15.Final, 4.1.135.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44249", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:3f89bdb8af4d3967ea8557497a5ec6ec4bbea5225424ad5f608a515cbbbbfc2f", + "Title": "netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation", + "Description": "Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-284", + "CWE-697", + "CWE-1287" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26017", + "https://access.redhat.com/errata/RHSA-2026:26018", + "https://access.redhat.com/errata/RHSA-2026:26586", + "https://access.redhat.com/errata/RHSA-2026:28573", + "https://access.redhat.com/errata/RHSA-2026:34608", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:37390", + "https://access.redhat.com/errata/RHSA-2026:41951", + "https://access.redhat.com/errata/RHSA-2026:48124", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49700", + "https://access.redhat.com/errata/RHSA-2026:49701", + "https://access.redhat.com/errata/RHSA-2026:53644", + "https://access.redhat.com/errata/RHSA-2026:53806", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/security/cve/CVE-2026-44249", + "https://bugzilla.redhat.com/show_bug.cgi?id=2488081", + "https://github.com/netty/netty", + "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final", + "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final", + "https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44249", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json", + "https://www.cve.org/CVERecord?id=CVE-2026-44249" + ], + "PublishedDate": "2026-06-11T22:16:56.707Z", + "LastModifiedDate": "2026-08-14T13:18:50.577Z" + }, + { + "VulnerabilityID": "CVE-2026-45416", + "VendorIDs": [ + "GHSA-x4gw-5cx5-pgmh" + ], + "PkgName": "io.netty:netty-handler", + "PkgPath": "usr/local/lib/igv/netty-handler-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-handler@4.1.118.Final", + "UID": "312bbec760e08bac" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.2.15.Final, 4.1.135.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-45416", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:153098006dbbe91b72c5dba08a6d610796eb082f94af13ad90a847d19e08bf82", + "Title": "netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake", + "Description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26017", + "https://access.redhat.com/errata/RHSA-2026:26018", + "https://access.redhat.com/errata/RHSA-2026:26586", + "https://access.redhat.com/errata/RHSA-2026:28573", + "https://access.redhat.com/errata/RHSA-2026:34608", + "https://access.redhat.com/errata/RHSA-2026:37390", + "https://access.redhat.com/errata/RHSA-2026:41951", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49700", + "https://access.redhat.com/errata/RHSA-2026:49701", + "https://access.redhat.com/errata/RHSA-2026:53644", + "https://access.redhat.com/errata/RHSA-2026:53806", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/security/cve/CVE-2026-45416", + "https://bugzilla.redhat.com/show_bug.cgi?id=2488391", + "https://github.com/netty/netty", + "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final", + "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final", + "https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh", + "https://nvd.nist.gov/vuln/detail/CVE-2026-45416", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45416.json", + "https://www.cve.org/CVERecord?id=CVE-2026-45416" + ], + "PublishedDate": "2026-06-12T15:16:26.94Z", + "LastModifiedDate": "2026-08-14T13:18:57.597Z" + }, + { + "VulnerabilityID": "CVE-2026-50010", + "VendorIDs": [ + "GHSA-c653-97m9-rcg9" + ], + "PkgName": "io.netty:netty-handler", + "PkgPath": "usr/local/lib/igv/netty-handler-4.1.118.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/io.netty/netty-handler@4.1.118.Final", + "UID": "312bbec760e08bac" + }, + "InstalledVersion": "4.1.118.Final", + "FixedVersion": "4.2.15.Final, 4.1.135.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:705ca2d1679693f3120d8f489e8e9254ab7da7608bf6d2b9923702e14ee28097", + "DiffID": "sha256:acdabbb6eb606cb25ea16fd710f2c0c3f2f6bce20fac4f38d831b943c9aac746" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-50010", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:64d8c5308986f6d708019401023c420d1287a6fc29844e0e2258c94b195aec67", + "Title": "netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass", + "Description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-347" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26017", + "https://access.redhat.com/errata/RHSA-2026:26018", + "https://access.redhat.com/errata/RHSA-2026:26586", + "https://access.redhat.com/errata/RHSA-2026:28573", + "https://access.redhat.com/errata/RHSA-2026:34608", + "https://access.redhat.com/errata/RHSA-2026:37390", + "https://access.redhat.com/errata/RHSA-2026:41951", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49700", + "https://access.redhat.com/errata/RHSA-2026:49701", + "https://access.redhat.com/errata/RHSA-2026:53644", + "https://access.redhat.com/errata/RHSA-2026:53806", + "https://access.redhat.com/security/cve/CVE-2026-50010", + "https://bugzilla.redhat.com/show_bug.cgi?id=2488429", + "https://github.com/netty/netty", + "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final", + "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final", + "https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9", + "https://nvd.nist.gov/vuln/detail/CVE-2026-50010", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50010.json", + "https://www.cve.org/CVERecord?id=CVE-2026-50010" + ], + "PublishedDate": "2026-06-12T16:16:31.18Z", + "LastModifiedDate": "2026-08-14T13:19:00.45Z" + } + ], + "vulnerability_count": 11 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 11 + } +} diff --git a/bfx/impute2/trivy-scan-results.json b/bfx/impute2/trivy-scan-results.json new file mode 100644 index 00000000..2e388f50 --- /dev/null +++ b/bfx/impute2/trivy-scan-results.json @@ -0,0 +1,16 @@ +{ + "tool": "impute2", + "scan_timestamp": "2026-08-16T17:08:11Z", + "workflow_run_id": "31960542324", + "versions": { + "2.3.2": { + "image": "ghcr.io/bundlecore/products/bfx/impute2:2.3.2", + "vulnerabilities": [], + "vulnerability_count": 0 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/instrain/trivy-scan-results.json b/bfx/instrain/trivy-scan-results.json new file mode 100644 index 00000000..0b419fd9 --- /dev/null +++ b/bfx/instrain/trivy-scan-results.json @@ -0,0 +1,2010 @@ +{ + "tool": "instrain", + "scan_timestamp": "2026-08-16T17:08:13Z", + "workflow_run_id": "31960542324", + "versions": { + "1.10.0": { + "image": "ghcr.io/bundlecore/products/bfx/instrain:1.10.0", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2025-6176", + "VendorIDs": [ + "GHSA-2qfp-q593-8484" + ], + "PkgName": "Brotli", + "PkgPath": "usr/local/lib/python3.8/site-packages/Brotli-1.0.9.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/brotli@1.0.9", + "UID": "64ed1f5548057eea" + }, + "InstalledVersion": "1.0.9", + "FixedVersion": "1.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-6176", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:09a9bc570dcd39f5f20bcc46567288ebf34af46e1580450ffccb155f9d204118", + "Title": "Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS", + "Description": "Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:2042", + "https://access.redhat.com/security/cve/CVE-2025-6176", + "https://bugzilla.redhat.com/2408762", + "https://bugzilla.redhat.com/show_bug.cgi?id=2408762", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6176", + "https://errata.almalinux.org/9/ALSA-2026-2042.html", + "https://errata.rockylinux.org/RLSA-2026:2042", + "https://github.com/google/brotli", + "https://github.com/google/brotli/commit/67d78bc41db1a0d03f2e763497748f2f69946627", + "https://github.com/google/brotli/issues/1327", + "https://github.com/google/brotli/issues/1375", + "https://github.com/google/brotli/pull/1234", + "https://github.com/google/brotli/releases/tag/v1.2.0", + "https://github.com/scrapy/scrapy/commit/14737e91edc513967f516fc839cc9c8a4f8d91da", + "https://github.com/scrapy/scrapy/pull/7134", + "https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0", + "https://linux.oracle.com/cve/CVE-2025-6176.html", + "https://linux.oracle.com/errata/ELSA-2026-2389.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-6176", + "https://www.cve.org/CVERecord?id=CVE-2025-6176" + ], + "PublishedDate": "2025-10-31T00:15:37.333Z", + "LastModifiedDate": "2026-06-17T10:01:19.72Z" + }, + { + "VulnerabilityID": "CVE-2026-23949", + "VendorIDs": [ + "GHSA-58pv-8j8x-9vj2" + ], + "PkgName": "jaraco.context", + "PkgPath": "usr/local/lib/python3.8/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jaraco.context@5.3.0", + "UID": "149d3b88e096e21b" + }, + "InstalledVersion": "5.3.0", + "FixedVersion": "6.1.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-23949", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:4ff23254fad0663c4b67e26aebcaa611646c6ff7a9e51de57492282781204f29", + "Title": "jaraco.context: jaraco.context: Path traversal via malicious tar archives", + "Description": "jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow attackers to extract files outside the intended extraction directory when malicious tar archives are processed. The strip_first_component filter splits the path on the first `/` and extracts the second component, while allowing `../` sequences. Paths like `dummy_dir/../../etc/passwd` become `../../etc/passwd`. Note that this suffers from a nested tarball attack as well with multi-level tar files such as `dummy_dir/inner.tar.gz`, where the inner.tar.gz includes a traversal `dummy_dir/../../config/.env` that also gets translated to `../../config/.env`. Version 6.1.0 contains a patch for the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 8.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 8.6 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-23949", + "https://github.com/jaraco/jaraco.context", + "https://github.com/jaraco/jaraco.context/blob/main/jaraco/context/__init__.py#L74-L91", + "https://github.com/jaraco/jaraco.context/commit/7b26a42b525735e4085d2e994e13802ea339d5f9", + "https://github.com/jaraco/jaraco.context/security/advisories/GHSA-58pv-8j8x-9vj2", + "https://github.com/pypa/setuptools/blob/main/setuptools/_vendor/jaraco/context.py#L55-L76", + "https://nvd.nist.gov/vuln/detail/CVE-2026-23949", + "https://ubuntu.com/security/notices/USN-7979-1", + "https://www.cve.org/CVERecord?id=CVE-2026-23949" + ], + "PublishedDate": "2026-01-20T01:15:57.723Z", + "LastModifiedDate": "2026-06-17T10:22:20.2Z" + }, + { + "VulnerabilityID": "CVE-2026-25990", + "VendorIDs": [ + "GHSA-cfh3-3jmp-rvhc" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25990", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:45a46b69b0163e37ae674e650c37f664a2d14e14ac165a50993604c2ea2ac962", + "Title": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image", + "Description": "Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/02/12/1", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:14873", + "https://access.redhat.com/errata/RHSA-2026:14874", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:28385", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:4128", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6308", + "https://access.redhat.com/errata/RHSA-2026:6309", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/security/cve/CVE-2026-25990", + "https://bugzilla.redhat.com/show_bug.cgi?id=2439170", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199", + "https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa", + "https://github.com/python-pillow/Pillow/pull/9427", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25990", + "https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json", + "https://ubuntu.com/security/notices/USN-8047-1", + "https://www.cve.org/CVERecord?id=CVE-2026-25990" + ], + "PublishedDate": "2026-02-11T21:16:20.67Z", + "LastModifiedDate": "2026-08-12T12:18:09.957Z" + }, + { + "VulnerabilityID": "CVE-2026-40192", + "VendorIDs": [ + "GHSA-whj4-6x5x-4v2j" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40192", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f7c62c08eb132d5ba8c87b7697be4ce7182d52258228a5dff078bec13e8261e9", + "Title": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing", + "Description": "Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770", + "CWE-409" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:16008", + "https://access.redhat.com/errata/RHSA-2026:16009", + "https://access.redhat.com/errata/RHSA-2026:16030", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:17609", + "https://access.redhat.com/errata/RHSA-2026:17611", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22629", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24866", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:34366", + "https://access.redhat.com/errata/RHSA-2026:34368", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/security/cve/CVE-2026-40192", + "https://bugzilla.redhat.com/show_bug.cgi?id=2458856", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628", + "https://github.com/python-pillow/Pillow/pull/9521", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40192", + "https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json", + "https://ubuntu.com/security/notices/USN-8211-1", + "https://www.cve.org/CVERecord?id=CVE-2026-40192" + ], + "PublishedDate": "2026-04-15T23:16:10.053Z", + "LastModifiedDate": "2026-08-12T12:19:09.49Z" + }, + { + "VulnerabilityID": "CVE-2026-42311", + "VendorIDs": [ + "GHSA-pwv6-vv43-88gr" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42311", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:dadb26931a57d1a6d1538ae8b88a127f3252495b8f932f1af0df1a0b957026a0", + "Title": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing", + "Description": "Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42311", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea", + "https://github.com/python-pillow/Pillow/pull/9520", + "https://github.com/python-pillow/Pillow/releases/tag/12.2.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42311", + "https://ubuntu.com/security/notices/USN-8399-1", + "https://www.cve.org/CVERecord?id=CVE-2026-42311" + ], + "PublishedDate": "2026-05-09T06:16:10.43Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-54058", + "VendorIDs": [ + "GHSA-62p4-gmf7-7g93" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54058", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b5f490a5c1e0f627baadf75e29d11331f5318003ad0dab860bc8defb5de2bd93", + "Title": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-54058", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d", + "https://github.com/python-pillow/Pillow/pull/9719", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93", + "https://linux.oracle.com/cve/CVE-2026-54058.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54058", + "https://www.cve.org/CVERecord?id=CVE-2026-54058" + ], + "PublishedDate": "2026-07-14T17:17:03.433Z", + "LastModifiedDate": "2026-08-06T15:46:05.867Z" + }, + { + "VulnerabilityID": "CVE-2026-54059", + "VendorIDs": [ + "GHSA-8v84-f9pq-wr9x" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54059", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:91534fa4be35ce6205b47ae93cdf8216571ca703eb014d8b0ae2631a5df2c2ff", + "Title": "python-pillow: Pillow: Denial of Service via crafted PCF font data", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54059", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2253.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x", + "https://linux.oracle.com/cve/CVE-2026-54059.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54059", + "https://www.cve.org/CVERecord?id=CVE-2026-54059" + ], + "PublishedDate": "2026-07-06T19:17:08.127Z", + "LastModifiedDate": "2026-07-07T18:58:26.73Z" + }, + { + "VulnerabilityID": "CVE-2026-54060", + "VendorIDs": [ + "GHSA-5x94-69rx-g8h2" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54060", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:5e943cf6ce1164078750bd746c002a92ef6d757f22ca2dd99ff677e296202625", + "Title": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54060", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2", + "https://linux.oracle.com/cve/CVE-2026-54060.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54060", + "https://www.cve.org/CVERecord?id=CVE-2026-54060" + ], + "PublishedDate": "2026-07-06T19:17:08.27Z", + "LastModifiedDate": "2026-07-07T18:58:45.827Z" + }, + { + "VulnerabilityID": "CVE-2026-55379", + "VendorIDs": [ + "GHSA-45hq-cxwh-f6vc" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55379", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:549bba3fb9b97cff6b47277a1d824f2d3e4c97e222b201ebcb26ee4a42c2f549", + "Title": "python-pillow: Pillow: Denial of Service via crafted BDF font file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55379", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2255.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc", + "https://linux.oracle.com/cve/CVE-2026-55379.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55379", + "https://www.cve.org/CVERecord?id=CVE-2026-55379" + ], + "PublishedDate": "2026-07-06T19:17:08.577Z", + "LastModifiedDate": "2026-07-07T18:59:01.817Z" + }, + { + "VulnerabilityID": "CVE-2026-55380", + "VendorIDs": [ + "GHSA-phj9-mv4w-65pm" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55380", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:2dfe229872db2b32bec2d33d15110f6cfea6330bd40e4ca2886c037ece05c8c2", + "Title": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55380", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2256.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm", + "https://linux.oracle.com/cve/CVE-2026-55380.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55380", + "https://www.cve.org/CVERecord?id=CVE-2026-55380" + ], + "PublishedDate": "2026-07-06T19:17:08.703Z", + "LastModifiedDate": "2026-07-07T18:58:54.647Z" + }, + { + "VulnerabilityID": "CVE-2026-59197", + "VendorIDs": [ + "GHSA-xj96-63gp-2gmr" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59197", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:973d22a3be721602ce313396da6efdbe15ee3f3b48de8e647a4075498b15c851", + "Title": "Pillow: Pillow: Native heap out-of-bounds write", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-59197", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1", + "https://github.com/python-pillow/Pillow/pull/9695", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr", + "https://linux.oracle.com/cve/CVE-2026-59197.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59197", + "https://www.cve.org/CVERecord?id=CVE-2026-59197" + ], + "PublishedDate": "2026-07-14T17:17:14.487Z", + "LastModifiedDate": "2026-07-21T19:17:11.907Z" + }, + { + "VulnerabilityID": "CVE-2026-59199", + "VendorIDs": [ + "GHSA-6r8x-57c9-28j4" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59199", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:d36f020958594b1d2f79abbd8858c25f97ffbf28b48dfb98aa086e9fbeffd145", + "Title": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59199", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3451.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b", + "https://github.com/python-pillow/Pillow/pull/9703", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59199", + "https://www.cve.org/CVERecord?id=CVE-2026-59199" + ], + "PublishedDate": "2026-07-14T16:17:01.937Z", + "LastModifiedDate": "2026-07-15T16:16:49.487Z" + }, + { + "VulnerabilityID": "CVE-2026-59200", + "VendorIDs": [ + "GHSA-jjj6-mw9f-p565" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59200", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f757608e1f1e95e242de04b48531590ab2a12f6d5c594c78f6b2bda1e84a2583", + "Title": "Pillow: Pillow: Denial of service via crafted PDF stream", + "Description": "Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59200", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09", + "https://github.com/python-pillow/Pillow/pull/9718", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59200", + "https://www.cve.org/CVERecord?id=CVE-2026-59200" + ], + "PublishedDate": "2026-07-14T17:17:14.62Z", + "LastModifiedDate": "2026-07-21T15:52:40.107Z" + }, + { + "VulnerabilityID": "CVE-2026-59204", + "VendorIDs": [ + "GHSA-vjc4-5qp5-m44j" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59204", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:1e90c3ef3a5c1d322cb91ff979ab281d20fd41c98ed7aa0af7e7d06cff366c94", + "Title": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image", + "Description": "Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59204", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca", + "https://github.com/python-pillow/Pillow/pull/9704", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59204", + "https://www.cve.org/CVERecord?id=CVE-2026-59204" + ], + "PublishedDate": "2026-07-14T16:17:02.227Z", + "LastModifiedDate": "2026-07-21T19:17:12.02Z" + }, + { + "VulnerabilityID": "CVE-2026-59205", + "VendorIDs": [ + "GHSA-9hw9-ch79-4vh6" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.8/site-packages/pillow-10.4.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@10.4.0", + "UID": "5d7817189fcbbc7" + }, + "InstalledVersion": "10.4.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59205", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b9dd23f1f491d25d06303caa65d98cf089b6f5ba150fd992f614a6f6afebaa21", + "Title": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59205", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3453.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721", + "https://github.com/python-pillow/Pillow/pull/9715", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59205", + "https://www.cve.org/CVERecord?id=CVE-2026-59205" + ], + "PublishedDate": "2026-07-14T16:17:02.37Z", + "LastModifiedDate": "2026-07-14T20:09:27.77Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgName": "setuptools", + "PkgPath": "usr/local/lib/python3.8/site-packages/setuptools-75.3.0-py3.13.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@75.3.0", + "UID": "c11a603939dac66e" + }, + "InstalledVersion": "75.3.0", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b28ee65a44cddca2f5fd121ec55f9b849a51989da5dc3477561686131f1b093d", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:13578", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/9/ALSA-2025-13578.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + }, + { + "VulnerabilityID": "CVE-2025-66418", + "VendorIDs": [ + "GHSA-gm62-xv2j-4w53" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.8/site-packages/urllib3-2.2.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.3", + "UID": "3d88a5abb813682d" + }, + "InstalledVersion": "2.2.3", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66418", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:39d909d5c02aa17aeedddbde711d4eac0f6705659891899ff6ba95aef1558b18", + "Title": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66418", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53", + "https://linux.oracle.com/cve/CVE-2025-66418.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66418", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://www.cve.org/CVERecord?id=CVE-2025-66418", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T16:15:51.053Z", + "LastModifiedDate": "2026-06-17T09:56:48.383Z" + }, + { + "VulnerabilityID": "CVE-2025-66471", + "VendorIDs": [ + "GHSA-2xpw-w6gg-jr37" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.8/site-packages/urllib3-2.2.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.3", + "UID": "3d88a5abb813682d" + }, + "InstalledVersion": "2.2.3", + "FixedVersion": "2.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-66471", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:e984353b06d26a1dc9204ea1f97f21ae974d8b31939bb917f1b1ac05276f62ca", + "Title": "urllib3: urllib3 Streaming API improperly handles highly compressed data", + "Description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/security/cve/CVE-2025-66471", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37", + "https://linux.oracle.com/cve/CVE-2025-66471.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-66471", + "https://ubuntu.com/security/notices/USN-7927-1", + "https://ubuntu.com/security/notices/USN-7927-2", + "https://ubuntu.com/security/notices/USN-7927-3", + "https://ubuntu.com/security/notices/USN-8344-1", + "https://ubuntu.com/security/notices/USN-8344-2", + "https://ubuntu.com/security/notices/USN-8344-3", + "https://www.cve.org/CVERecord?id=CVE-2025-66471", + "https://www.openwall.com/lists/oss-security/2025/12/05/4" + ], + "PublishedDate": "2025-12-05T17:16:04.4Z", + "LastModifiedDate": "2026-06-17T09:56:53.65Z" + }, + { + "VulnerabilityID": "CVE-2026-21441", + "VendorIDs": [ + "GHSA-38jv-5279-wg99" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.8/site-packages/urllib3-2.2.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.3", + "UID": "3d88a5abb813682d" + }, + "InstalledVersion": "2.2.3", + "FixedVersion": "2.6.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-21441", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:ebc76797c0d74f3bace054955997a1e8ec66bcfe3b758595e8a23d8e09a61c8f", + "Title": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)", + "Description": "urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V3Score": 7.5, + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0981", + "https://access.redhat.com/errata/RHSA-2026:0990", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:1038", + "https://access.redhat.com/errata/RHSA-2026:1041", + "https://access.redhat.com/errata/RHSA-2026:1042", + "https://access.redhat.com/errata/RHSA-2026:1086", + "https://access.redhat.com/errata/RHSA-2026:1087", + "https://access.redhat.com/errata/RHSA-2026:1088", + "https://access.redhat.com/errata/RHSA-2026:1089", + "https://access.redhat.com/errata/RHSA-2026:1166", + "https://access.redhat.com/errata/RHSA-2026:1168", + "https://access.redhat.com/errata/RHSA-2026:1176", + "https://access.redhat.com/errata/RHSA-2026:1224", + "https://access.redhat.com/errata/RHSA-2026:1226", + "https://access.redhat.com/errata/RHSA-2026:1239", + "https://access.redhat.com/errata/RHSA-2026:1240", + "https://access.redhat.com/errata/RHSA-2026:1241", + "https://access.redhat.com/errata/RHSA-2026:1254", + "https://access.redhat.com/errata/RHSA-2026:1485", + "https://access.redhat.com/errata/RHSA-2026:14877", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:1546", + "https://access.redhat.com/errata/RHSA-2026:1596", + "https://access.redhat.com/errata/RHSA-2026:1599", + "https://access.redhat.com/errata/RHSA-2026:1609", + "https://access.redhat.com/errata/RHSA-2026:1618", + "https://access.redhat.com/errata/RHSA-2026:1619", + "https://access.redhat.com/errata/RHSA-2026:1652", + "https://access.redhat.com/errata/RHSA-2026:1674", + "https://access.redhat.com/errata/RHSA-2026:1676", + "https://access.redhat.com/errata/RHSA-2026:1693", + "https://access.redhat.com/errata/RHSA-2026:1704", + "https://access.redhat.com/errata/RHSA-2026:1706", + "https://access.redhat.com/errata/RHSA-2026:1712", + "https://access.redhat.com/errata/RHSA-2026:1717", + "https://access.redhat.com/errata/RHSA-2026:1726", + "https://access.redhat.com/errata/RHSA-2026:1729", + "https://access.redhat.com/errata/RHSA-2026:1730", + "https://access.redhat.com/errata/RHSA-2026:1734", + "https://access.redhat.com/errata/RHSA-2026:1735", + "https://access.redhat.com/errata/RHSA-2026:1736", + "https://access.redhat.com/errata/RHSA-2026:17456", + "https://access.redhat.com/errata/RHSA-2026:17457", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17461", + "https://access.redhat.com/errata/RHSA-2026:17462", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:1791", + "https://access.redhat.com/errata/RHSA-2026:1792", + "https://access.redhat.com/errata/RHSA-2026:1793", + "https://access.redhat.com/errata/RHSA-2026:1794", + "https://access.redhat.com/errata/RHSA-2026:1803", + "https://access.redhat.com/errata/RHSA-2026:1805", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:1957", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2126", + "https://access.redhat.com/errata/RHSA-2026:2137", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2144", + "https://access.redhat.com/errata/RHSA-2026:2256", + "https://access.redhat.com/errata/RHSA-2026:2456", + "https://access.redhat.com/errata/RHSA-2026:2500", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:2563", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2717", + "https://access.redhat.com/errata/RHSA-2026:2718", + "https://access.redhat.com/errata/RHSA-2026:2723", + "https://access.redhat.com/errata/RHSA-2026:2728", + "https://access.redhat.com/errata/RHSA-2026:2760", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2764", + "https://access.redhat.com/errata/RHSA-2026:2765", + "https://access.redhat.com/errata/RHSA-2026:28043", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2911", + "https://access.redhat.com/errata/RHSA-2026:2919", + "https://access.redhat.com/errata/RHSA-2026:2924", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:2926", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:33154", + "https://access.redhat.com/errata/RHSA-2026:3406", + "https://access.redhat.com/errata/RHSA-2026:3444", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:44696", + "https://access.redhat.com/errata/RHSA-2026:51357", + "https://access.redhat.com/errata/RHSA-2026:5459", + "https://access.redhat.com/errata/RHSA-2026:6287", + "https://access.redhat.com/errata/RHSA-2026:6292", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8500", + "https://access.redhat.com/errata/RHSA-2026:8501", + "https://access.redhat.com/security/cve/CVE-2026-21441", + "https://bugzilla.redhat.com/2419455", + "https://bugzilla.redhat.com/2419467", + "https://bugzilla.redhat.com/2427726", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2419467", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427726", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66418", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66471", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21441", + "https://errata.almalinux.org/9/ALSA-2026-1239.html", + "https://errata.rockylinux.org/RLSA-2026:1087", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99", + "https://linux.oracle.com/cve/CVE-2026-21441.html", + "https://linux.oracle.com/errata/ELSA-2026-1254.html", + "https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-21441", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json", + "https://ubuntu.com/security/notices/USN-7955-1", + "https://ubuntu.com/security/notices/USN-7955-2", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2026-21441" + ], + "PublishedDate": "2026-01-07T22:15:44.04Z", + "LastModifiedDate": "2026-08-14T13:17:38.737Z" + }, + { + "VulnerabilityID": "CVE-2026-44431", + "VendorIDs": [ + "GHSA-qccp-gfcp-xxvc" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.8/site-packages/urllib3-2.2.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.2.3", + "UID": "3d88a5abb813682d" + }, + "InstalledVersion": "2.2.3", + "FixedVersion": "2.7.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44431", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:7b134db3efa80203c555dd38f9da11be551a51f37e65a72cff2507b0896825bc", + "Title": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers", + "Description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V3Score": 5.3, + "V40Score": 8.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:28158", + "https://access.redhat.com/errata/RHSA-2026:28159", + "https://access.redhat.com/security/cve/CVE-2026-44431", + "https://bugzilla.redhat.com/2477154", + "https://bugzilla.redhat.com/2477167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477154", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477167", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432", + "https://errata.almalinux.org/9/ALSA-2026-28159.html", + "https://errata.rockylinux.org/RLSA-2026:28158", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc", + "https://linux.oracle.com/cve/CVE-2026-44431.html", + "https://linux.oracle.com/errata/ELSA-2026-49927.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44431", + "https://ubuntu.com/security/notices/USN-8379-1", + "https://www.cve.org/CVERecord?id=CVE-2026-44431" + ], + "PublishedDate": "2026-05-13T16:16:57.15Z", + "LastModifiedDate": "2026-06-26T12:16:32.423Z" + }, + { + "VulnerabilityID": "CVE-2026-24049", + "VendorIDs": [ + "GHSA-8rrh-rw8j-w5fx" + ], + "PkgName": "wheel", + "PkgPath": "usr/local/lib/python3.8/site-packages/setuptools/_vendor/wheel-0.43.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/wheel@0.43.0", + "UID": "c7ca25bcec95e4fa" + }, + "InstalledVersion": "0.43.0", + "FixedVersion": "0.46.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-24049", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c80fa24f211faf7e8a990bd1d1971b20fc11c18644ea2fb5e075e9603957e4f6", + "Title": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking", + "Description": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22", + "CWE-732" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", + "V3Score": 5.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:1902", + "https://access.redhat.com/errata/RHSA-2026:1939", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:2090", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2675", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2694", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2710", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2823", + "https://access.redhat.com/errata/RHSA-2026:2865", + "https://access.redhat.com/errata/RHSA-2026:2866", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5119", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6555", + "https://access.redhat.com/errata/RHSA-2026:6562", + "https://access.redhat.com/errata/RHSA-2026:6565", + "https://access.redhat.com/errata/RHSA-2026:7250", + "https://access.redhat.com/security/cve/CVE-2026-24049", + "https://bugzilla.redhat.com/2431959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2431959", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24049", + "https://errata.almalinux.org/9/ALSA-2026-1939.html", + "https://errata.rockylinux.org/RLSA-2026:1939", + "https://github.com/pypa/wheel", + "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef", + "https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e", + "https://github.com/pypa/wheel/releases/tag/0.46.2", + "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx", + "https://linux.oracle.com/cve/CVE-2026-24049.html", + "https://linux.oracle.com/errata/ELSA-2026-2090.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-24049", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json", + "https://ubuntu.com/security/notices/USN-8221-1", + "https://www.cve.org/CVERecord?id=CVE-2026-24049" + ], + "PublishedDate": "2026-01-22T05:16:23.157Z", + "LastModifiedDate": "2026-08-12T12:17:55.967Z" + }, + { + "VulnerabilityID": "CVE-2026-24049", + "VendorIDs": [ + "GHSA-8rrh-rw8j-w5fx" + ], + "PkgName": "wheel", + "PkgPath": "usr/local/lib/python3.8/site-packages/wheel-0.45.1.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/wheel@0.45.1", + "UID": "96a2fc8795aa5f8a" + }, + "InstalledVersion": "0.45.1", + "FixedVersion": "0.46.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:7e7fc1b2d6585f1c5cfbdf2e3cb2a0901334247c1581cc9f16b7fb84942bd16b", + "DiffID": "sha256:f8998462dcb897e283858ba80fd348c6a642a49454463421a9d6d8bb9310addd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-24049", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c80fa24f211faf7e8a990bd1d1971b20fc11c18644ea2fb5e075e9603957e4f6", + "Title": "wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking", + "Description": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22", + "CWE-732" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", + "V3Score": 5.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:1504", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:1902", + "https://access.redhat.com/errata/RHSA-2026:1939", + "https://access.redhat.com/errata/RHSA-2026:1942", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:2090", + "https://access.redhat.com/errata/RHSA-2026:2106", + "https://access.redhat.com/errata/RHSA-2026:2139", + "https://access.redhat.com/errata/RHSA-2026:2675", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2694", + "https://access.redhat.com/errata/RHSA-2026:2695", + "https://access.redhat.com/errata/RHSA-2026:2710", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:2762", + "https://access.redhat.com/errata/RHSA-2026:2823", + "https://access.redhat.com/errata/RHSA-2026:2865", + "https://access.redhat.com/errata/RHSA-2026:2866", + "https://access.redhat.com/errata/RHSA-2026:2900", + "https://access.redhat.com/errata/RHSA-2026:2925", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:4185", + "https://access.redhat.com/errata/RHSA-2026:4215", + "https://access.redhat.com/errata/RHSA-2026:4271", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5119", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6555", + "https://access.redhat.com/errata/RHSA-2026:6562", + "https://access.redhat.com/errata/RHSA-2026:6565", + "https://access.redhat.com/errata/RHSA-2026:7250", + "https://access.redhat.com/security/cve/CVE-2026-24049", + "https://bugzilla.redhat.com/2431959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2431959", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24049", + "https://errata.almalinux.org/9/ALSA-2026-1939.html", + "https://errata.rockylinux.org/RLSA-2026:1939", + "https://github.com/pypa/wheel", + "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef", + "https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e", + "https://github.com/pypa/wheel/releases/tag/0.46.2", + "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx", + "https://linux.oracle.com/cve/CVE-2026-24049.html", + "https://linux.oracle.com/errata/ELSA-2026-2090.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-24049", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json", + "https://ubuntu.com/security/notices/USN-8221-1", + "https://www.cve.org/CVERecord?id=CVE-2026-24049" + ], + "PublishedDate": "2026-01-22T05:16:23.157Z", + "LastModifiedDate": "2026-08-12T12:17:55.967Z" + } + ], + "vulnerability_count": 22 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 22 + } +} diff --git a/bfx/interproscan/trivy-scan-results.json b/bfx/interproscan/trivy-scan-results.json new file mode 100644 index 00000000..170c6a26 --- /dev/null +++ b/bfx/interproscan/trivy-scan-results.json @@ -0,0 +1,29692 @@ +{ + "tool": "interproscan", + "scan_timestamp": "2026-08-16T17:08:20Z", + "workflow_run_id": "31960542324", + "versions": { + "5.59-91.0": { + "image": "ghcr.io/bundlecore/products/bfx/interproscan:5.59-91.0", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2023-40743", + "VendorIDs": [ + "GHSA-rmqp-9w4c-gc7w" + ], + "PkgName": "axis:axis", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/axis.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/axis/axis@1.2-RC1", + "UID": "d01e46eab4903ec1" + }, + "InstalledVersion": "1.2-RC1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-40743", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:9b42e5144913584ed2950e2afee381a53a7539b2ad4c6bfd0ca23ad0470cf774", + "Title": "** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an ...", + "Description": "** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through \"ServiceFactory.getService\" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE.\n\nAs Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to \"ServiceFactory.getService\", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does not expect to create an Axis 1.x release fixing this problem, though contributors that would like to work towards this are welcome.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-20", + "CWE-75" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 4, + "nvd": 4, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.8, + "V40Score": 9.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://github.com/apache/axis-axis1-java", + "https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210", + "https://lists.apache.org/thread/gs0qgk2mgss7zfhzdd6ftfjvm4kp7v82", + "https://lists.debian.org/debian-lts-announce/2023/10/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-40743", + "https://ubuntu.com/security/notices/USN-6470-1", + "https://www.cve.org/CVERecord?id=CVE-2023-40743", + "https://www.openwall.com/lists/oss-security/2023/09/05/1" + ], + "PublishedDate": "2023-09-05T15:15:42.687Z", + "LastModifiedDate": "2026-06-17T06:19:19.003Z" + }, + { + "VulnerabilityID": "CVE-2019-0227", + "VendorIDs": [ + "GHSA-h9gj-rqrw-x4fq" + ], + "PkgName": "axis:axis", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/axis.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/axis/axis@1.2-RC1", + "UID": "d01e46eab4903ec1" + }, + "InstalledVersion": "1.2-RC1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-0227", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:aacb553716d0bf87b93257665f2ff9a2d7c471bbc2dbee6751f26c0a40a98126", + "Title": "axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.", + "Description": "A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-918" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 1 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:A/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 5.4, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2019-0227", + "https://lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd@%3Cjava-user.axis.apache.org%3E", + "https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E", + "https://nvd.nist.gov/vuln/detail/CVE-2019-0227", + "https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis", + "https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/", + "https://security.netapp.com/advisory/ntap-20240621-0006", + "https://security.netapp.com/advisory/ntap-20240621-0006/", + "https://www.cve.org/CVERecord?id=CVE-2019-0227", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html", + "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html" + ], + "PublishedDate": "2019-05-01T21:29:00.643Z", + "LastModifiedDate": "2026-06-17T02:08:02.19Z" + }, + { + "VulnerabilityID": "CVE-2023-51441", + "VendorIDs": [ + "GHSA-hr2c-p8rh-238h" + ], + "PkgName": "axis:axis", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/axis.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/axis/axis@1.2-RC1", + "UID": "d01e46eab4903ec1" + }, + "InstalledVersion": "1.2-RC1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-51441", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:8471e19f0df3106faf1b9caf75d10516a500e1bfc5929582ba9106b31ac4997c", + "Title": "** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerabilit ...", + "Description": "** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF\nThis issue affects Apache Axis: through 1.3.\n\nAs Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. Alternatively you could use a build of Axis with the patch from https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06 applied. The Apache Axis project does not expect to create an Axis 1.x release \nfixing this problem, though contributors that would like to work towards\n this are welcome.\n\n", + "Severity": "HIGH", + "CweIDs": [ + "CWE-918" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.2 + } + }, + "References": [ + "https://github.com/apache/axis-axis1-java", + "https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06", + "https://lists.apache.org/thread/8nrm5thop8f82pglx4o0jg8wmvy6d9yd", + "https://nvd.nist.gov/vuln/detail/CVE-2023-51441" + ], + "PublishedDate": "2024-01-06T12:15:42.997Z", + "LastModifiedDate": "2026-06-17T06:40:57.88Z" + }, + { + "VulnerabilityID": "CVE-2025-52999", + "VendorIDs": [ + "GHSA-h46c-h94j-95f3" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-core", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-core-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.9.8", + "UID": "efd98d62f2d9c650" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.15.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-52999", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:5c1ebb8d7e77a104566fa0442add5eb7973c0dbd246422a2d80e00871724f297", + "Title": "com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError", + "Description": "jackson-core contains core low-level incremental (\"streaming\") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:12280", + "https://access.redhat.com/security/cve/CVE-2025-52999", + "https://bugzilla.redhat.com/2374804", + "https://bugzilla.redhat.com/show_bug.cgi?id=2374804", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52999", + "https://errata.almalinux.org/9/ALSA-2025-12280.html", + "https://errata.rockylinux.org/RLSA-2025:12280", + "https://github.com/FasterXML/jackson-core", + "https://github.com/FasterXML/jackson-core/pull/943", + "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-h46c-h94j-95f3", + "https://linux.oracle.com/cve/CVE-2025-52999.html", + "https://linux.oracle.com/errata/ELSA-2025-14126.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-52999", + "https://www.cve.org/CVERecord?id=CVE-2025-52999" + ], + "PublishedDate": "2025-06-25T17:15:39.82Z", + "LastModifiedDate": "2026-06-17T09:37:27.057Z" + }, + { + "VulnerabilityID": "GHSA-r7wm-3cxj-wff9", + "PkgName": "com.fasterxml.jackson.core:jackson-core", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-core-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.9.8", + "UID": "efd98d62f2d9c650" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.18.8, 2.21.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:4217d0da215179a943880df36c910255498a991fa19f6d2e9edbe98bb3b7d004", + "Title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)", + "Description": "## Summary\n\nThe fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq](https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq) (Number Length Constraint Bypass in Async Parser, published 2026-02-28) is incomplete. The fix commit `b0c428e6` (#1555) wired `validateIntegerLength` into a new `_setIntLength` helper and called it at every place where the integer portion of a number is *decided* (terminator byte arrived, `.` / `e/E` seen, end-of-feed inside a fully-buffered value). It did not call it on the much more attacker-relevant path: \"ran out of input while still inside `MINOR_NUMBER_INTEGER_DIGITS`, return `NOT_AVAILABLE` to caller\".\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, can keep the parser inside `MINOR_NUMBER_INTEGER_DIGITS` indefinitely. `_textBuffer.expandCurrentSegment()` grows on every chunk, and `validateIntegerLength` is never invoked. The accumulator is only gated by `maxStringLength` (20 MiB default) — a **~20,000x amplification** of the documented `maxNumberLength` (1000 default).\n\nThis is the same vulnerability class, same advisory wording (\"Memory Exhaustion: Unbounded allocation in TextBuffer from excessively long numbers\"), same parser class — just the streaming path the original fix didn't cover. The fix to the *fraction* path is correct (see `_finishFloatFraction` at line 1834-1837 of `NonBlockingUtf8JsonParserBase.java` in 2.18.6, where `_setFractLength(fractLen)` IS called before the `NOT_AVAILABLE` return); the equivalent call is missing from every integer-digit path.\n\n## Affected versions\n\nVerified on the patched releases:\n- `com.fasterxml.jackson.core:jackson-core` **2.18.6**\n- `com.fasterxml.jackson.core:jackson-core` **2.21.1**\n\nStructurally identical code in `tools.jackson.core` 3.0.x / 3.1.x — same `NonBlockingUtf8JsonParserBase` class, same `_setIntLength` rollout, same NOT_AVAILABLE returns without validation. Not retested but presumed vulnerable.\n\n## Affected code\n\n[`src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java`](https://github.com/FasterXML/jackson-core/blob/b0c428e6/src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java) in 2.18.6 / 2.21.1.\n\n### Site 1 — `_startPositiveNumber(int ch)` lines 1320-1330:\n\n```java\nif (outPtr >= outBuf.length) {\n // NOTE: must expand to ensure contents all in a single buffer (to keep\n // other parts of parsing simpler)\n outBuf = _textBuffer.expandCurrentSegment();\n}\noutBuf[outPtr++] = (char) ch;\nif (++_inputPtr >= _inputEnd) {\n _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n _textBuffer.setCurrentLength(outPtr);\n return _updateTokenToNA(); // <-- no validateIntegerLength(outPtr)\n}\n```\n\n### Site 2 — `_finishNumberIntegralPart` lines 1691-1727:\n\n```java\nprotected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n int negMod = _numberNegative ? -1 : 0;\n\n while (true) {\n if (_inputPtr >= _inputEnd) {\n _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n _textBuffer.setCurrentLength(outPtr);\n return _updateTokenToNA(); // <-- no validateIntegerLength(outPtr + negMod)\n }\n int ch = getByteFromBuffer(_inputPtr) & 0xFF;\n if (ch < INT_0) {\n if (ch == INT_PERIOD) {\n _setIntLength(outPtr+negMod); // <-- validated here\n ++_inputPtr;\n return _startFloat(outBuf, outPtr, ch);\n }\n break;\n }\n if (ch > INT_9) {\n if ((ch | 0x20) == INT_e) {\n _setIntLength(outPtr+negMod); // <-- validated here\n ++_inputPtr;\n return _startFloat(outBuf, outPtr, ch);\n }\n break;\n }\n ++_inputPtr;\n if (outPtr >= outBuf.length) {\n outBuf = _textBuffer.expandCurrentSegment();\n }\n outBuf[outPtr++] = (char) ch;\n }\n _setIntLength(outPtr+negMod); // <-- validated here\n _textBuffer.setCurrentLength(outPtr);\n return _valueComplete(JsonToken.VALUE_NUMBER_INT);\n}\n```\n\nThe pattern recurs at lines 1297, 1329, 1343, 1365, 1395, 1409, 1437, 1467, 1481, 1586, 1644, 1698 — every \"ran out of input mid-integer\" exit returns to the caller without validating the accumulator length.\n\n### Compare with the fraction path that is correct\n\n`_finishFloatFraction` lines 1827-1838:\n\n```java\nwhile (loop) {\n if (ch >= INT_0 && ch <= INT_9) {\n ++fractLen;\n if (outPtr >= outBuf.length) {\n outBuf = _textBuffer.expandCurrentSegment();\n }\n outBuf[outPtr++] = (char) ch;\n if (_inputPtr >= _inputEnd) {\n _textBuffer.setCurrentLength(outPtr);\n _setFractLength(fractLen); // <-- VALIDATED\n return JsonToken.NOT_AVAILABLE;\n }\n ch = getNextSignedByteFromBuffer();\n }\n ...\n}\n```\n\n## Impact\n\nReactive frameworks (Spring WebFlux / Reactor, Quarkus, Helidon, Vert.x JSON, anything wrapping `JsonFactory.createNonBlockingByteArrayParser()` or `createNonBlockingByteBufferParser()`) feed inbound HTTP/gRPC bytes to the async parser as they arrive. Operators who set `StreamReadConstraints.builder().maxNumberLength(N)` on the assumption that this caps memory per number value are not getting that guarantee in chunked-feed scenarios. The parser silently accumulates digits up to `maxStringLength` (20 MiB default) per concurrent connection. Multiply by attacker-controlled concurrency to OOM the JVM.\n\nThe synchronous parsers (`UTF8StreamJsonParser`, `ReaderBasedJsonParser`) and the async parser on *complete* input are not affected — those paths go through `_setIntLength` or `ParserBase._reportTooLongIntegral` correctly.\n\nCWE-770 (Allocation of Resources Without Limits or Throttling), CVSS roughly the same as the parent advisory (Network / Low complexity / High availability impact). The parent advisory was scored CVSS 8.7 High.\n\n## Proof of concept\n\nStandalone PoC, no Maven required:\n\n```\nmkdir poc && cd poc\ncurl -sLo jackson-core-2.18.6.jar https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-core/2.18.6/jackson-core-2.18.6.jar\ncat > PoC.java <<'EOF'\nimport com.fasterxml.jackson.core.*;\nimport com.fasterxml.jackson.core.async.ByteArrayFeeder;\n\npublic class PoC {\n public static void main(String[] args) throws Exception {\n StreamReadConstraints strict = StreamReadConstraints.builder()\n .maxNumberLength(1000)\n .build();\n JsonFactory f = new JsonFactoryBuilder()\n .streamReadConstraints(strict)\n .build();\n\n // Sanity: synchronous parser rejects 5000-digit int.\n try (JsonParser p = f.createParser(\"{\\\"v\\\":\" + \"1\".repeat(5000) + \"}\")) {\n while (p.nextToken() != null) { /* drive */ }\n System.out.println(\"[-] BUG ABSENT: sync parser accepted\");\n return;\n } catch (Exception e) {\n System.out.println(\"[+] sync parser rejected 5000-digit int: \" + e.getClass().getSimpleName());\n }\n\n // Bug: async parser, chunked, no terminator.\n JsonParser ap = f.createNonBlockingByteArrayParser();\n ByteArrayFeeder feeder = (ByteArrayFeeder) ap;\n\n byte[] preamble = \"{\\\"v\\\":\".getBytes(\"UTF-8\");\n feeder.feedInput(preamble, 0, preamble.length);\n while (ap.nextToken() != JsonToken.NOT_AVAILABLE) { /* drain */ }\n\n byte[] digits = new byte[16 * 1024];\n for (int i = 0; i < digits.length; i++) digits[i] = (byte) ('1' + (i % 9));\n\n for (int c = 0; c < 600; c++) {\n feeder.feedInput(digits, 0, digits.length);\n JsonToken t = ap.nextToken();\n if (t != JsonToken.NOT_AVAILABLE) {\n System.out.println(\"[-] unexpected token: \" + t);\n return;\n }\n }\n System.out.println(\"[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\");\n\n // Closing the number now finally triggers the validator.\n feeder.feedInput(\"}\".getBytes(\"UTF-8\"), 0, 1);\n feeder.endOfInput();\n try {\n while (ap.nextToken() != null) { /* drive */ }\n } catch (Exception e) {\n System.out.println(\"[*] late rejection on close: \" + e.getMessage().split(\"\\n\")[0]);\n }\n ap.close();\n }\n}\nEOF\njavac -cp jackson-core-2.18.6.jar PoC.java\njava -Xmx256m -cp jackson-core-2.18.6.jar:. PoC\n```\n\nObserved output against `jackson-core-2.18.6`:\n\n```\n[+] sync parser rejected 5000-digit int: StreamConstraintsException\n[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\n[*] late rejection on close: Number value length (9830400) exceeds the maximum allowed (1000, from `StreamReadConstraints.getMaxNumberLength()`)\n```\n\nObserved output against `jackson-core-2.21.1`: identical.\n\nThe 9.83 MB figure is purely a function of the loop bound (600 chunks * 16 KiB). The actual ceiling is `maxStringLength = 20 MiB`. With the strict policy declared as `maxNumberLength = 1000`, the parser permits **9830x** more allocation than the policy allows. With `maxStringLength` left at the default 20 MiB, an attacker can drive a single connection to 40 MiB of `char[]` heap (chars are 2 bytes each) before the validator finally fires on terminator/`endOfInput()`. Multiply by concurrent connections.\n\n## End-to-end reproduction through real HTTP\n\nSupplements the standalone PoC with a running Spring Boot WebFlux server,\ndriving the same bug through the actual reactor-netty + Jackson2JsonDecoder\nstreaming-decode path that production reactive endpoints use.\n\nSetup:\n- Spring Boot 3.3.5 starter-webflux (spring-webflux 6.1.14, reactor-netty 1.1.23)\n- jackson-databind 2.17.2, jackson-core overridden:\n - VULN run: `com.fasterxml.jackson.core:jackson-core:2.18.7` (latest published)\n - PATCHED run: `2.18.8-SNAPSHOT` built from the fix branch\n- JVM: OpenJDK 17.0.18\n- Server `JsonFactory` configured with `StreamReadConstraints.builder().maxNumberLength(1000).build()`\n\nEndpoint under test exposes the `Flux` request body directly to\n`Jackson2JsonDecoder.decode(Flux, ResolvableType, ...)` so the parser sees one\nHTTP chunk per `feedInput` (the same pattern used for any\n`@RequestBody Flux<...>` / streaming JSON decoder in WebFlux). A raw-socket\nHTTP/1.1 chunked client streams `{\"v\":1` then 250 chunks of 200 digit bytes\neach (50,000 digits total) at 20ms intervals, then writes the closing `}`.\n\nVULN — jackson-core 2.18.7:\n```\n[VULN-SMALLCHUNK] streamed 50000 digits across 250 chunks; server still accepting\n[VULN-SMALLCHUNK] full POST sent (50000 digits). Response:\nHTTP/1.1 200 OK\nERR after 6548ms cause=com.fasterxml.jackson.core.exc.StreamConstraintsException:\n Number value length (50000) exceeds the maximum allowed (1000, ...)\n```\nServer-side controller trace (250 DataBuffer arrivals elided):\n```\n[ctrl] DataBuffer arrived size=6 ms=39 <- '{\"v\":1'\n[ctrl] DataBuffer arrived size=200 ms=42\n...\n[ctrl] DataBuffer arrived size=199 ms=5993\n[ctrl] DataBuffer arrived size=1 ms=6518 <- closing '}'\n[ctrl] ERR after 6548ms ... Number value length (50000) exceeds ...\n```\nServer held all 50,000 digit characters in `_textBuffer` for 6.5 seconds with\n`maxNumberLength=1000` declared. The validator never fires during streaming;\nit only fires at value-completion when the closing `}` arrives.\n\nPATCHED — jackson-core 2.18.8-SNAPSHOT (fix branch):\n```\n[PATCHED-SMALLCHUNK] connection broke after 2801 digits at chunk 14: [Errno 32] Broken pipe\n[PATCHED-SMALLCHUNK] DONE: digits_sent=2801 status=connection-broke-mid-stream\n```\nServer-side controller trace:\n```\n[ctrl] DataBuffer arrived size=6 ms=129\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=145\n[ctrl] DataBuffer arrived size=200 ms=146\n[ctrl] DataBuffer arrived size=200 ms=147\n[ctrl] ERR after 155ms ... Number value length (1001) exceeds the maximum allowed (1000, ...)\n```\nPatched server raises `StreamConstraintsException` at 155ms after only 5\nDataBuffers, exactly when the accumulated digit count crosses\n`maxNumberLength=1000`. The connection is reset mid-stream rather than the\nparser silently consuming the rest of the attacker's payload.\n\nSide-by-side:\n\n| Build | Chunks accepted before exception | Digits buffered | Time to detection |\n|---|---|---|---|\n| jackson-core 2.18.7 | 250 (full payload) | 50,000 (50x the configured limit) | 6,548ms — only at terminator |\n| 2.18.8-SNAPSHOT (fix branch) | 5 | 1,001 | 155ms — moment threshold crossed |\n\nNote on the default `@RequestBody Mono` path: that path cannot\ndistinguish the two builds because Spring's `decodeToMono` joins all\nDataBuffers into one before parsing. The exploitable shape is the\nstreaming-decode path (`Flux` / `@RequestBody Flux<...>` /\nWebSocket / SSE / any direct `decoder.decode(Flux, ...)` call),\nwhich is also what `Jackson2Tokenizer` uses for any streaming JSON\ndeserialization in WebFlux and Quarkus reactive REST.\n\n## Suggested fix\n\nMirror the pattern already used in `_finishFloatFraction`. At every site that returns `_updateTokenToNA()` (or `JsonToken.NOT_AVAILABLE`) with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`, call `_setIntLength(outPtr + negMod)` first. Concretely, the diff to `NonBlockingUtf8JsonParserBase.java` would be:\n\n```diff\n protected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n int negMod = _numberNegative ? -1 : 0;\n\n while (true) {\n if (_inputPtr >= _inputEnd) {\n _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n _textBuffer.setCurrentLength(outPtr);\n+ _streamReadConstraints.validateIntegerLength(outPtr + negMod);\n return _updateTokenToNA();\n }\n```\n\nNote: `_setIntLength` itself can't be used as-is because it also assigns `_intLength`, and `_intLength` must not be set until the integer is truly complete (subsequent fraction handling reads `_intLength`). The minimal fix is to call only the validator, as shown.\n\nApply the same one-line insertion before each `return _updateTokenToNA();` that exits with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`. The sites are listed above (12 lines total).\n\nAlternatively, a heavier refactor: also gate `_textBuffer.expandCurrentSegment()` calls inside the digit-accumulation loops on `outPtr < maxNumberLength` so that the validator fires at the moment the buffer would be enlarged past the limit, rather than waiting for the next chunk boundary. Either approach is sufficient.\n\n## Credit\n\nReported by `tonghuaroot` (`tonghuaroot@gmail.com`). Variant hunt against the Feb 2026 fix for GHSA-72hv-8253-57qq.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + } + }, + "References": [ + "https://github.com/FasterXML/jackson-core", + "https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd", + "https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641", + "https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8", + "https://github.com/FasterXML/jackson-core/pull/1611", + "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9" + ], + "PublishedDate": "2026-07-21T21:58:53Z", + "LastModifiedDate": "2026-08-03T20:30:41Z" + }, + { + "VulnerabilityID": "CVE-2019-14379", + "VendorIDs": [ + "GHSA-6fpp-rgj9-8rwc" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.9.2, 2.8.11.4, 2.7.9.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-14379", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:aa630aa4bf0c70bc400f19c6a3890c5fd9f67a1992eb1eeacb1002209bc186af", + "Title": "jackson-databind: default typing mishandling leading to remote code execution", + "Description": "SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-1321" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 4, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "http://seclists.org/fulldisclosure/2022/Mar/23", + "https://access.redhat.com/errata/RHBA-2019:2824", + "https://access.redhat.com/errata/RHSA-2019:2743", + "https://access.redhat.com/errata/RHSA-2019:2858", + "https://access.redhat.com/errata/RHSA-2019:2935", + "https://access.redhat.com/errata/RHSA-2019:2936", + "https://access.redhat.com/errata/RHSA-2019:2937", + "https://access.redhat.com/errata/RHSA-2019:2938", + "https://access.redhat.com/errata/RHSA-2019:2998", + "https://access.redhat.com/errata/RHSA-2019:3044", + "https://access.redhat.com/errata/RHSA-2019:3045", + "https://access.redhat.com/errata/RHSA-2019:3046", + "https://access.redhat.com/errata/RHSA-2019:3050", + "https://access.redhat.com/errata/RHSA-2019:3149", + "https://access.redhat.com/errata/RHSA-2019:3200", + "https://access.redhat.com/errata/RHSA-2019:3292", + "https://access.redhat.com/errata/RHSA-2019:3297", + "https://access.redhat.com/errata/RHSA-2019:3901", + "https://access.redhat.com/errata/RHSA-2020:0727", + "https://access.redhat.com/security/cve/CVE-2019-14379", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b", + "https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2", + "https://github.com/FasterXML/jackson-databind/issues/2387", + "https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E", + "https://lists.apache.org/thread.html/2766188be238a446a250ef76801037d452979152d85bce5e46805815@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/525bcf949a4b0da87a375cbad2680b8beccde749522f24c49befe7fb@%3Ccommits.pulsar.apache.org%3E", + "https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/689c6bcc6c7612eee71e453a115a4c8581e7b718537025d4b265783d@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/75f482fdc84abe6d0c8f438a76437c335a7bbeb5cddd4d70b4bc0cbf@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/859815b2e9f1575acbb2b260b73861c16ca49bca627fa0c46419051f@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/8723b52c2544e6cb804bc8a36622c584acd1bd6c53f2b6034c9fea54@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E", + "https://lists.apache.org/thread.html/99944f86abefde389da9b4040ea2327c6aa0b53a2ff9352bd4cfec17@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/d161ff3d59c5a8213400dd6afb1cce1fac4f687c32d1e0c0bfbfaa2d@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/e25e734c315f70d8876a846926cfe3bfa1a4888044f146e844caf72f@%3Ccommits.ambari.apache.org%3E", + "https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/f17f63b0f8a57e4a5759e01d25cffc0548f0b61ff5c6bfd704ad2f2a@%3Ccommits.ambari.apache.org%3E", + "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/", + "https://nvd.nist.gov/vuln/detail/CVE-2019-14379", + "https://security.netapp.com/advisory/ntap-20190814-0001", + "https://security.netapp.com/advisory/ntap-20190814-0001/", + "https://support.apple.com/kb/HT213189", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-14379", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html" + ], + "PublishedDate": "2019-07-29T12:15:16.633Z", + "LastModifiedDate": "2026-06-17T02:18:18.833Z" + }, + { + "VulnerabilityID": "CVE-2019-14540", + "VendorIDs": [ + "GHSA-h822-r4r5-v8jg" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10, 2.8.11.5, 2.6.7.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-14540", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:8bd5b09ea47f3f48e7dfb9fc7d2f49245d623e09564c8bd9554ef0fb02a0bab4", + "Title": "jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig", + "Description": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2019:3200", + "https://access.redhat.com/errata/RHSA-2020:0159", + "https://access.redhat.com/errata/RHSA-2020:0160", + "https://access.redhat.com/errata/RHSA-2020:0161", + "https://access.redhat.com/errata/RHSA-2020:0164", + "https://access.redhat.com/errata/RHSA-2020:0445", + "https://access.redhat.com/security/cve/CVE-2019-14540", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x", + "https://github.com/FasterXML/jackson-databind/commit/73c1c2cc76e6cdd7f3a5615cbe3207fe96e4d3db", + "https://github.com/FasterXML/jackson-databind/commit/d4983c740fec7d5576b207a8c30a63d3ea7443de", + "https://github.com/FasterXML/jackson-databind/issues/2410", + "https://github.com/FasterXML/jackson-databind/issues/2449", + "https://linux.oracle.com/cve/CVE-2019-14540.html", + "https://linux.oracle.com/errata/ELSA-2020-1644.html", + "https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E", + "https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016@%3Cissues.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9@%3Cissues.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E", + "https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0@%3Cissues.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb@%3Ccommits.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540@%3Ccommits.nifi.apache.org%3E", + "https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/", + "https://nvd.nist.gov/vuln/detail/CVE-2019-14540", + "https://seclists.org/bugtraq/2019/Oct/6", + "https://security.netapp.com/advisory/ntap-20191004-0002", + "https://security.netapp.com/advisory/ntap-20191004-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-14540", + "https://www.debian.org/security/2019/dsa-4542", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html" + ], + "PublishedDate": "2019-09-15T22:15:10.277Z", + "LastModifiedDate": "2026-06-17T02:18:36.947Z" + }, + { + "VulnerabilityID": "CVE-2019-16335", + "VendorIDs": [ + "GHSA-85cw-hj65-qqv9" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10, 2.8.11.5, 2.6.7.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-16335", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:4da38917bea09194de07054f6eb39f753b6580c147808398126556354ad883b6", + "Title": "jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource", + "Description": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2019:3200", + "https://access.redhat.com/errata/RHSA-2020:0159", + "https://access.redhat.com/errata/RHSA-2020:0160", + "https://access.redhat.com/errata/RHSA-2020:0161", + "https://access.redhat.com/errata/RHSA-2020:0164", + "https://access.redhat.com/errata/RHSA-2020:0445", + "https://access.redhat.com/errata/RHSA-2020:0729", + "https://access.redhat.com/security/cve/CVE-2019-16335", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/73c1c2cc76e6cdd7f3a5615cbe3207fe96e4d3db", + "https://github.com/FasterXML/jackson-databind/issues/2449", + "https://linux.oracle.com/cve/CVE-2019-16335.html", + "https://linux.oracle.com/errata/ELSA-2020-1644.html", + "https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E", + "https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016@%3Cissues.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9@%3Cissues.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E", + "https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0@%3Cissues.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb@%3Ccommits.hbase.apache.org%3E", + "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/", + "https://nvd.nist.gov/vuln/detail/CVE-2019-16335", + "https://seclists.org/bugtraq/2019/Oct/6", + "https://security.netapp.com/advisory/ntap-20191004-0002", + "https://security.netapp.com/advisory/ntap-20191004-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-16335", + "https://www.debian.org/security/2019/dsa-4542", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html" + ], + "PublishedDate": "2019-09-15T22:15:10.59Z", + "LastModifiedDate": "2026-06-17T02:22:08.803Z" + }, + { + "VulnerabilityID": "CVE-2019-16942", + "VendorIDs": [ + "GHSA-mx7p-6679-8g3q" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.1, 2.8.11.5, 2.6.7.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-16942", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:fb36eb884e4d581011a22379c3cad19cae628c0f19786c688c655363fe23a92d", + "Title": "jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.*", + "Description": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2019:3901", + "https://access.redhat.com/errata/RHSA-2020:0159", + "https://access.redhat.com/errata/RHSA-2020:0160", + "https://access.redhat.com/errata/RHSA-2020:0161", + "https://access.redhat.com/errata/RHSA-2020:0164", + "https://access.redhat.com/errata/RHSA-2020:0445", + "https://access.redhat.com/security/cve/CVE-2019-16942", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/328a0f833daf6baa443ac3b37c818a0204714b0b", + "https://github.com/FasterXML/jackson-databind/commit/54aa38d87dcffa5ccc23e64922e9536c82c1b9c8", + "https://github.com/FasterXML/jackson-databind/commit/9593e16cf5a3d289a9c584f7123639655de9ddac", + "https://github.com/FasterXML/jackson-databind/commit/bc67eb11a7cf57561f861ff16f879f1fceb5779f", + "https://github.com/FasterXML/jackson-databind/issues/2478", + "https://issues.apache.org/jira/browse/GEODE-7255", + "https://linux.oracle.com/cve/CVE-2019-16942.html", + "https://linux.oracle.com/errata/ELSA-2020-1644.html", + "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5@%3Cissues.geode.apache.org%3E", + "https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954@%3Cissues.geode.apache.org%3E", + "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370@%3Cissues.geode.apache.org%3E", + "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2019-16942", + "https://seclists.org/bugtraq/2019/Oct/6", + "https://security.netapp.com/advisory/ntap-20191017-0006", + "https://security.netapp.com/advisory/ntap-20191017-0006/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-16942", + "https://www.debian.org/security/2019/dsa-4542", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2019-10-01T17:15:10.323Z", + "LastModifiedDate": "2026-06-17T02:23:00.187Z" + }, + { + "VulnerabilityID": "CVE-2019-16943", + "VendorIDs": [ + "GHSA-fmmc-742q-jg75" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.1, 2.8.11.5, 2.6.7.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-16943", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:3faacf4f976b3bdff16551674a1174ddd7cfe3b2c421ff09c53479a04145ea36", + "Title": "jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource", + "Description": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2020:0159", + "https://access.redhat.com/errata/RHSA-2020:0160", + "https://access.redhat.com/errata/RHSA-2020:0161", + "https://access.redhat.com/errata/RHSA-2020:0164", + "https://access.redhat.com/errata/RHSA-2020:0445", + "https://access.redhat.com/security/cve/CVE-2019-16943", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/328a0f833daf6baa443ac3b37c818a0204714b0b", + "https://github.com/FasterXML/jackson-databind/commit/bc67eb11a7cf57561f861ff16f879f1fceb5779f", + "https://github.com/FasterXML/jackson-databind/issues/2478", + "https://linux.oracle.com/cve/CVE-2019-16943.html", + "https://linux.oracle.com/errata/ELSA-2020-1644.html", + "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd@%3Ccommits.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E", + "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2019-16943", + "https://seclists.org/bugtraq/2019/Oct/6", + "https://security.netapp.com/advisory/ntap-20191017-0006", + "https://security.netapp.com/advisory/ntap-20191017-0006/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-16943", + "https://www.debian.org/security/2019/dsa-4542", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2019-10-01T17:15:10.4Z", + "LastModifiedDate": "2026-06-17T02:23:00.493Z" + }, + { + "VulnerabilityID": "CVE-2019-17267", + "VendorIDs": [ + "GHSA-f3j5-rmmp-3fc5" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10, 2.8.11.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-17267", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:7666e66979e81c284e8d679e7d17433bca8f662ded5d9be9923ec5ffbc2582cc", + "Title": "jackson-databind: Serialization gadgets in classes of the ehcache package", + "Description": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 4, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2019:3200", + "https://access.redhat.com/errata/RHSA-2020:0159", + "https://access.redhat.com/errata/RHSA-2020:0160", + "https://access.redhat.com/errata/RHSA-2020:0161", + "https://access.redhat.com/errata/RHSA-2020:0164", + "https://access.redhat.com/errata/RHSA-2020:0445", + "https://access.redhat.com/security/cve/CVE-2019-17267", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/191a4cdf87b56d2ddddb77edd895ee756b7f75eb", + "https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10", + "https://github.com/FasterXML/jackson-databind/issues/2460", + "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a29461ccd9597a8@%3Cdev.skywalking.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html", + "https://nvd.nist.gov/vuln/detail/CVE-2019-17267", + "https://security.netapp.com/advisory/ntap-20191017-0006", + "https://security.netapp.com/advisory/ntap-20191017-0006/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-17267", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2019-10-07T00:15:10.49Z", + "LastModifiedDate": "2026-06-17T02:23:36.38Z" + }, + { + "VulnerabilityID": "CVE-2019-17531", + "VendorIDs": [ + "GHSA-gjmw-vf9h-g25v" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.1, 2.8.11.5, 2.6.7.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-17531", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:4625f44eb59fdbaeeca30892be0c24fa8512d8c926fd23483fe14d205ff32ab7", + "Title": "jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.*", + "Description": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 2, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2019:4192", + "https://access.redhat.com/errata/RHSA-2020:0159", + "https://access.redhat.com/errata/RHSA-2020:0160", + "https://access.redhat.com/errata/RHSA-2020:0161", + "https://access.redhat.com/errata/RHSA-2020:0164", + "https://access.redhat.com/errata/RHSA-2020:0445", + "https://access.redhat.com/security/cve/CVE-2019-17531", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/b5a304a98590b6bb766134f9261e6566dcbbb6d0", + "https://github.com/FasterXML/jackson-databind/issues/2498", + "https://linux.oracle.com/cve/CVE-2019-17531.html", + "https://linux.oracle.com/errata/ELSA-2020-1644.html", + "https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5@%3Ccommits.pulsar.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2019-17531", + "https://security.netapp.com/advisory/ntap-20191024-0005", + "https://security.netapp.com/advisory/ntap-20191024-0005/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-17531", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2019-10-12T21:15:08.57Z", + "LastModifiedDate": "2026-06-17T02:24:04.85Z" + }, + { + "VulnerabilityID": "CVE-2019-20330", + "VendorIDs": [ + "GHSA-gww7-p5w4-wrfv" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-20330", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:55555574253975130e14379ce9153c642f52bd6c7db0689abd540f2f57f0dd57", + "Title": "jackson-databind: lacks certain net.sf.ehcache blocking", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2019-20330", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/eb254813cc822d0af015ce8fe05febf50721dc53", + "https://github.com/FasterXML/jackson-databind/commit/fc4214a883dc087070f25da738ef0d49c2f3387e", + "https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2", + "https://github.com/FasterXML/jackson-databind/issues/2526", + "https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r2c77dd6ab8344285bd8e481b57cf3029965a4b0036eefccef74cdd44@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r3f8180d0d25a7c6473ebb9714b0c1d19a73f455ae70d0c5fefc17e6c@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r428735963bee7cb99877b88d3228e28ec28af64646455c4f3e7a3c94@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r50f513772f12e1babf65c7c2b9c16425bac2d945351879e2e267517f@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r5c14fdcabdeaba258857bcb67198652e4dce1d33ddc590cd81d82393@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r5c3644c97f0434d1ceb48ff48897a67bdbf3baf7efbe7d04625425b3@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r5d3d10fdf28110da3f9ac1b7d08d7e252f98d7d37ce0a6bd139a2e4f@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r67f4d4c48197454b83d62afbed8bebbda3764e6e3a6e26a848961764@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r707d23bb9ee245f50aa909add0da6e8d8f24719b1278ddd99d2428b2@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r7a0821b44247a1e6c6fe5f2943b90ebc4f80a8d1fb0aa9a8b29a59a2@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r7fb123e7dad49af5886cfec7135c0fd5b74e4c67af029e1dc91ba744@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r8831b7fa5ca87a1cf23ee08d6dedb7877a964c1d2bd869af24056a63@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99@%3Cissues.zookeeper.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html", + "https://nvd.nist.gov/vuln/detail/CVE-2019-20330", + "https://security.netapp.com/advisory/ntap-20200127-0004", + "https://security.netapp.com/advisory/ntap-20200127-0004/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-20330", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2020-01-03T04:15:12.137Z", + "LastModifiedDate": "2026-06-17T02:30:16.127Z" + }, + { + "VulnerabilityID": "CVE-2020-8840", + "VendorIDs": [ + "GHSA-4w82-r329-3q67" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.6.7.4, 2.7.9.7, 2.8.11.5, 2.9.10.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-8840", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:06d5dd0eac7a85704321748cbf00a94001af737fe632bb5c5250c70a9dc90f5e", + "Title": "jackson-databind: Lacks certain xbean-reflect/JNDI blocking", + "Description": "FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-01-fastjason-en", + "https://access.redhat.com/security/cve/CVE-2020-8840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/74aba4042fce35ee0b91bd2847e788c10040d78b", + "https://github.com/FasterXML/jackson-databind/commit/914e7c9f2cb8ce66724bf26a72adc7e958992497", + "https://github.com/FasterXML/jackson-databind/commit/9bb52c7122271df75435ec7e66ecf6b02b1ee14f", + "https://github.com/FasterXML/jackson-databind/issues/2620", + "https://lists.apache.org/thread.html/r078e68a926ea6be12e8404e47f45aabf04bb4668e8265c0de41db6db@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r1c09b9551f6953dbeca190a4c4b78198cdbb9825fce36f96fe3d8218@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/r1efc776fc6ce3387593deaa94bbdd296733b1b01408a39c8d1ab9e0e@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/r2fa8046bd47fb407ca09b5107a80fa6147ba4ebe879caae5c98b7657@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/r319f19c74e06c201b9d4e8b282a4e4b2da6dcda022fb46f007dd00d3@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r3539bd3a377991217d724879d239e16e86001c54160076408574e1da@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r3d20a2660b36551fd8257d479941782af4a7169582449fac1704bde2@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r428d068b2a4923f1a5a4f5fc6381b95205cfe7620169d16db78e9c71@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r446646c5588b10f5e02409ad580b12f314869009cdfbf844ca395cec@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/r46bebdeb59b8b7212d63a010ca445a9f5c4e9d64dcf693cab6f399d3@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r5d8bea8e9d17b6efcf4a0e4e194e91ef46a99f505777a31a60da2b38@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/r65ee95fa09c831843bac81eaa582fdddc2b6119912a72d1c83a9b882@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r6fdd4c61a09a0c89f581b4ddb3dc6f154ab0c705fcfd0a7358b2e4e5@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r7762d69e85c58d6948823424017ef4c08f47de077644277fa18cc116@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/r7e5c10534ed06bf805473ac85e8412fe3908a8fa4cabf5027bf11220@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r8170007fd9b263d65b37d92a7b5d7bc357aedbb113a32838bc4a9485@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r8e96c340004b7898cad3204ea51280ef6e4b553a684e1452bf1b18b1@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r94930e39b60fff236160c1c4110fe884dc093044b067aa5fc98d7ee1@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/r9e59ebaf76fd00b2fa3ff5ebf18fe075ca9f4376216612c696f76718@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/r9ecf211c22760b00967ebe158c6ed7dba9142078e2a630ab8904a5b7@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ra275f29615f35d5b40106d1582a41e5388b2a5131564e9e01a572987@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/rac5ee5d686818be7e7c430d35108ee01a88aae54f832d32f62431fd1@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rb43f9a65150948a6bebd3cb77ee3e105d40db2820fd547528f4e7f89@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rb5eedf90ba3633e171a2ffdfe484651c9490dc5df74c8a29244cbc0e@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rb73708bf714ed6dbc1212da082e7703e586077f0c92f3940b2e82caf@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/rb99c7321eba5d4c907beec46675d52827528b738cfafd48eb4d862f1@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/rc717fd6c65190f4e592345713f9ef0723fb7d71f624caa2a17caa26a@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/rcc72b497e3dff2dc62ec9b89ceb90bc4e1b14fc56c3c252a6fcbb013@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/rdea588d4a0ebf9cb7ce8c3a8f18d0d306507c4f8ba178dd3d20207b8@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/rdf311f13e6356297e0ffe74397fdd25a3687b0a16e687c3ff5b834d8@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/rdf8d389271a291dde3b2f99c36918d6cb1e796958af626cc140fee23@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/re7326b8655eab931f2a9ce074fd9a1a51b5db11456bee9b48e1e170c@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/re8ae2670ec456ef1c5a2a661a2838ab2cd00e9efa1e88c069f546f21@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.apache.org/thread.html/rf28ab6f224b48452afd567dfffb705fbda0fdbbf6535f6bc69d47e91@%3Cdev.ranger.apache.org%3E", + "https://lists.apache.org/thread.html/rfc1ccfe89332155b72ce17f13a2701d3e7b9ec213324ceb90e79a28a@%3Cdev.ranger.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-8840", + "https://security.netapp.com/advisory/ntap-20200327-0002", + "https://security.netapp.com/advisory/ntap-20200327-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-8840", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2020-02-10T21:56:10.653Z", + "LastModifiedDate": "2026-06-17T03:27:02.403Z" + }, + { + "VulnerabilityID": "CVE-2020-9546", + "VendorIDs": [ + "GHSA-5p34-5m6p-p58g" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-9546", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:d6c7e535e4bc52086c64d6dd94485ea1b902f5873ccf81e4bb39d656c156ae55", + "Title": "jackson-databind: Serialization gadgets in shaded-hikari-config", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-9546", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/issues/2631", + "https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-9546", + "https://security.netapp.com/advisory/ntap-20200904-0006", + "https://security.netapp.com/advisory/ntap-20200904-0006/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-9546", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-02T04:15:10.843Z", + "LastModifiedDate": "2026-06-17T03:28:07.543Z" + }, + { + "VulnerabilityID": "CVE-2020-9547", + "VendorIDs": [ + "GHSA-q93h-jc49-78gg" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4, 2.8.11.6, 2.7.9.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-9547", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:869029ef69430d36eb100081ed63c9ad40d15fd8e5c9b531ebace387a2eda0aa", + "Title": "jackson-databind: Serialization gadgets in ibatis-sqlmap", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-9547", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c88787e235ae2", + "https://github.com/FasterXML/jackson-databind/issues/2634", + "https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r4accb2e0de9679174efd3d113a059bab71ff3ec53e882790d21c1cc1@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r742ef70d126548dcf7de5be5779355c9d76a9aec71d7a9ef02c6398a@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ra3e90712f2d59f8cef03fa796f5adf163d32b81fe7b95385f21790e6@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rc0d5d0f72da1ed6fc5e438b1ddb3fa090c73006b55f873cf845375ab@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rd0e958d6d5c5ee16efed73314cd0e445c8dbb4bdcc80fc9d1d6c11fc@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/redbe4f1e21bf080f637cf9fbec47729750a2f443a919765360337428@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-9547", + "https://security.netapp.com/advisory/ntap-20200904-0006", + "https://security.netapp.com/advisory/ntap-20200904-0006/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-9547", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-02T04:15:11.017Z", + "LastModifiedDate": "2026-06-17T03:28:07.76Z" + }, + { + "VulnerabilityID": "CVE-2020-9548", + "VendorIDs": [ + "GHSA-p43x-xfjf-5jhr" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4, 2.8.11.6, 2.7.9.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-9548", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:f415894446f2b3cf91cc7313cb772f19238a5d06638ab4c33a18667f63d8052b", + "Title": "jackson-databind: Serialization gadgets in anteros-core", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-9548", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/1e64db6a2fad331f96c7363fda3bc5f3dffa25bb", + "https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c88787e235ae2", + "https://github.com/FasterXML/jackson-databind/issues/2634", + "https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-9548", + "https://security.netapp.com/advisory/ntap-20200904-0006", + "https://security.netapp.com/advisory/ntap-20200904-0006/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-9548", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-02T04:15:11.077Z", + "LastModifiedDate": "2026-06-17T03:28:08.023Z" + }, + { + "VulnerabilityID": "CVE-2019-12086", + "VendorIDs": [ + "GHSA-5ww9-j83m-q7qx" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.9, 2.8.11.4, 2.7.9.6, 2.6.7.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-12086", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:a27a26e020e35827eaf7a367385ae86fe4a95bfede1e9a5cedbe39fb21d21719", + "Title": "jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server.", + "Description": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "http://russiansecurity.expert/2016/04/20/mysql-connect-file-read/", + "http://www.securityfocus.com/bid/109227", + "https://access.redhat.com/errata/RHSA-2019:2858", + "https://access.redhat.com/errata/RHSA-2019:2935", + "https://access.redhat.com/errata/RHSA-2019:2936", + "https://access.redhat.com/errata/RHSA-2019:2937", + "https://access.redhat.com/errata/RHSA-2019:2938", + "https://access.redhat.com/errata/RHSA-2019:2998", + "https://access.redhat.com/errata/RHSA-2019:3044", + "https://access.redhat.com/errata/RHSA-2019:3045", + "https://access.redhat.com/errata/RHSA-2019:3046", + "https://access.redhat.com/errata/RHSA-2019:3050", + "https://access.redhat.com/errata/RHSA-2019:3149", + "https://access.redhat.com/errata/RHSA-2019:3200", + "https://access.redhat.com/security/cve/CVE-2019-12086", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/d30f036208ab1c60bd5ce429cb4f7f1a3e5682e8", + "https://github.com/FasterXML/jackson-databind/commit/dda513bd7251b4f32b7b60b1c13740e3b5a43024", + "https://github.com/FasterXML/jackson-databind/commit/efc3c0d02f4743dbaa6d1b9c466772a2f13d966b", + "https://github.com/FasterXML/jackson-databind/issues/2326", + "https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.9", + "https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E", + "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/88cd25375805950ae7337e669b0cb0eeda98b9604c1b8d806dccbad2@%3Creviews.spark.apache.org%3E", + "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E", + "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E", + "https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E", + "https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E", + "https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679@%3Ccommits.nifi.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/05/msg00030.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2019-12086", + "https://seclists.org/bugtraq/2019/May/68", + "https://security.netapp.com/advisory/ntap-20190530-0003", + "https://security.netapp.com/advisory/ntap-20190530-0003/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://web.archive.org/web/20200227030031/http://www.securityfocus.com/bid/109227", + "https://web.archive.org/web/20200808181049/http://russiansecurity.expert/2016/04/20/mysql-connect-file-read", + "https://www.cve.org/CVERecord?id=CVE-2019-12086", + "https://www.debian.org/security/2019/dsa-4452", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html", + "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html" + ], + "PublishedDate": "2019-05-17T17:29:00.483Z", + "LastModifiedDate": "2026-06-17T02:14:01.907Z" + }, + { + "VulnerabilityID": "CVE-2019-14439", + "VendorIDs": [ + "GHSA-gwp4-hfv6-p7hw" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.9.2, 2.8.11.4, 2.7.9.6, 2.6.7.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-14439", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:ba4c08dbd398a4dc8e1898385ce0f3ad32727836e16136a5a2abd71b6e62bf4f", + "Title": "jackson-databind: Polymorphic typing issue related to logback/JNDI", + "Description": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2019:3200", + "https://access.redhat.com/security/cve/CVE-2019-14439", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b", + "https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2", + "https://github.com/FasterXML/jackson-databind/issues/2389", + "https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E", + "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E", + "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E", + "https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E", + "https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E", + "https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/", + "https://nvd.nist.gov/vuln/detail/CVE-2019-14439", + "https://seclists.org/bugtraq/2019/Oct/6", + "https://security.netapp.com/advisory/ntap-20190814-0001", + "https://security.netapp.com/advisory/ntap-20190814-0001/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2019-14439", + "https://www.debian.org/security/2019/dsa-4542", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpujan2020.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html" + ], + "PublishedDate": "2019-07-30T11:15:11.123Z", + "LastModifiedDate": "2026-06-17T02:18:25.93Z" + }, + { + "VulnerabilityID": "CVE-2019-14892", + "VendorIDs": [ + "GHSA-cf6r-3wgc-h863" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.6.7.3, 2.8.11.5, 2.9.10", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-14892", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:2febf8c452d8a2fa1c018228a4a3cfa383a517426a490c191c842daddcb0d191", + "Title": "jackson-databind: Serialization gadgets in classes of the commons-configuration package", + "Description": "A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200", + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 4, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2020:0729", + "https://access.redhat.com/security/cve/CVE-2019-14892", + "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/41b7f9b90149e9d44a65a8261a8deedc7186f6af", + "https://github.com/FasterXML/jackson-databind/commit/819cdbcab51c6da9fb896380f2d46e9b7d4fdc3b", + "https://github.com/FasterXML/jackson-databind/issues/2462", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://nvd.nist.gov/vuln/detail/CVE-2019-14892", + "https://security.netapp.com/advisory/ntap-20200904-0005", + "https://security.netapp.com/advisory/ntap-20200904-0005/", + "https://www.cve.org/CVERecord?id=CVE-2019-14892" + ], + "PublishedDate": "2020-03-02T17:15:17.813Z", + "LastModifiedDate": "2026-06-17T02:19:15.487Z" + }, + { + "VulnerabilityID": "CVE-2019-14893", + "VendorIDs": [ + "GHSA-qmqc-x3r4-6v39" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-14893", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:df520f8ccd7053c5fcb072b08f2342770edbd28e314519596468d64c70f8424c", + "Title": "jackson-databind: Serialization gadgets in classes of the xalan package", + "Description": "A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200", + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 4, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2020:0729", + "https://access.redhat.com/security/cve/CVE-2019-14893", + "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14893", + "https://github.com/FasterXML/jackson-databind/commit/998efd708284778f29d83d7962a9bd935c228317", + "https://github.com/FasterXML/jackson-databind/issues/2469", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://nvd.nist.gov/vuln/detail/CVE-2019-14893", + "https://security.netapp.com/advisory/ntap-20200327-0006", + "https://security.netapp.com/advisory/ntap-20200327-0006/", + "https://www.cve.org/CVERecord?id=CVE-2019-14893", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2020-03-02T21:15:17.52Z", + "LastModifiedDate": "2026-06-17T02:19:15.637Z" + }, + { + "VulnerabilityID": "CVE-2020-10650", + "VendorIDs": [ + "GHSA-rpr3-cw39-3pxh" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-10650", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:1f61061b23cfe6d75d55e7947b0429e29550021fde4be7a29d58c28079358445", + "Title": "A deserialization flaw was discovered in jackson-databind through 2.9. ...", + "Description": "A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/a424c038ba0c0d65e579e22001dec925902ac0ef", + "https://github.com/FasterXML/jackson-databind/issues/2658", + "https://github.com/FasterXML/jackson-databind/pull/2864", + "https://github.com/advisories/GHSA-rpr3-cw39-3pxh", + "https://github.com/luisgarciacheckmarx/LGV_onefile/issues/19", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00032.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-10650", + "https://security.netapp.com/advisory/ntap-20230818-0007", + "https://security.netapp.com/advisory/ntap-20230818-0007/", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpuoct2022.html" + ], + "PublishedDate": "2022-12-26T20:15:10.433Z", + "LastModifiedDate": "2026-06-17T02:48:10.007Z" + }, + { + "VulnerabilityID": "CVE-2020-10672", + "VendorIDs": [ + "GHSA-95cm-88f5-f2c7" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-10672", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:9106bbd2fe8cc5c9bacb48accd7cedefcc253cd3e80181a3d63cdf85ed50115b", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-10672", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88", + "https://github.com/FasterXML/jackson-databind/commit/592872f4235c7f2a3280725278da55544032f72d", + "https://github.com/FasterXML/jackson-databind/issues/2659", + "https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-10672", + "https://security.netapp.com/advisory/ntap-20200403-0002", + "https://security.netapp.com/advisory/ntap-20200403-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-10672", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-18T22:15:12.313Z", + "LastModifiedDate": "2026-06-17T02:48:13.527Z" + }, + { + "VulnerabilityID": "CVE-2020-10673", + "VendorIDs": [ + "GHSA-fqwf-pjwf-7vqv" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4, 2.6.7.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-10673", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:7d3c03245ba33ef049058ec930ac4a4862535a83c49292892f06e2f9714824a3", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-10673", + "https://bugzilla.redhat.com/show_bug.cgi?id=1535313", + "https://bugzilla.redhat.com/show_bug.cgi?id=1655438", + "https://bugzilla.redhat.com/show_bug.cgi?id=1656786", + "https://bugzilla.redhat.com/show_bug.cgi?id=1698084", + "https://bugzilla.redhat.com/show_bug.cgi?id=1744095", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755831", + "https://bugzilla.redhat.com/show_bug.cgi?id=1755849", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758187", + "https://bugzilla.redhat.com/show_bug.cgi?id=1758191", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767125", + "https://bugzilla.redhat.com/show_bug.cgi?id=1767131", + "https://bugzilla.redhat.com/show_bug.cgi?id=1775293", + "https://bugzilla.redhat.com/show_bug.cgi?id=1777032", + "https://bugzilla.redhat.com/show_bug.cgi?id=1782486", + "https://bugzilla.redhat.com/show_bug.cgi?id=1795215", + "https://bugzilla.redhat.com/show_bug.cgi?id=1802006", + "https://bugzilla.redhat.com/show_bug.cgi?id=1806840", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807371", + "https://bugzilla.redhat.com/show_bug.cgi?id=1807421", + "https://bugzilla.redhat.com/show_bug.cgi?id=1809210", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16335", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16942", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16943", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17531", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20330", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10672", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8840", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9547", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548", + "https://errata.almalinux.org/8/ALSA-2020-1644.html", + "https://errata.rockylinux.org/RLSA-2020:1644", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/1645efbd392989cf015f459a91c999e59c921b15", + "https://github.com/FasterXML/jackson-databind/issues/2660", + "https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-10673", + "https://security.netapp.com/advisory/ntap-20200403-0002", + "https://security.netapp.com/advisory/ntap-20200403-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-10673", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-18T22:15:12.407Z", + "LastModifiedDate": "2026-06-17T02:48:13.82Z" + }, + { + "VulnerabilityID": "CVE-2020-10968", + "VendorIDs": [ + "GHSA-rf6r-2c4q-2vwg" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-10968", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:2794068832189f0c8a5798a0877ded806c175fe9b8d30949b6e62053dd01ef0b", + "Title": "jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvider", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-10968", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/05d7e0e13f43e12db6a51726df12c8b4d8040676", + "https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88", + "https://github.com/FasterXML/jackson-databind/issues/2662", + "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-10968", + "https://security.netapp.com/advisory/ntap-20200403-0002", + "https://security.netapp.com/advisory/ntap-20200403-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-10968", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-26T13:15:12.97Z", + "LastModifiedDate": "2026-06-17T02:48:46.243Z" + }, + { + "VulnerabilityID": "CVE-2020-10969", + "VendorIDs": [ + "GHSA-758m-v56v-grj4" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-10969", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:0356af9efb59132a5f77b579d4df4127049862484cf54b6472edeb1203aefc0a", + "Title": "jackson-databind: Serialization gadgets in javax.swing.JEditorPane", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-10969", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/6ba48457984943df0de92c54144f7dcae01b1221", + "https://github.com/FasterXML/jackson-databind/issues/2642", + "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-10969", + "https://security.netapp.com/advisory/ntap-20200403-0002", + "https://security.netapp.com/advisory/ntap-20200403-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-10969", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-26T13:15:13.077Z", + "LastModifiedDate": "2026-06-17T02:48:46.523Z" + }, + { + "VulnerabilityID": "CVE-2020-11111", + "VendorIDs": [ + "GHSA-v3xw-c963-f5hc" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-11111", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:51ff10c3c30e2c59c3ebab4eba2d20f5703d62ee518fffe384a9d8ddb1e9641e", + "Title": "jackson-databind: Serialization gadgets in org.apache.activemq.jms.pool.XaPooledConnectionFactory", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-11111", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/issues/2664", + "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-11111", + "https://security.netapp.com/advisory/ntap-20200403-0002", + "https://security.netapp.com/advisory/ntap-20200403-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-11111", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-31T05:15:13.007Z", + "LastModifiedDate": "2026-06-17T02:49:04.183Z" + }, + { + "VulnerabilityID": "CVE-2020-11112", + "VendorIDs": [ + "GHSA-58pp-9c76-5625" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-11112", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:0692213af498dd92125c5b7739d1bdbb60210c82a5bb2bca9ea7121a805275ed", + "Title": "jackson-databind: Serialization gadgets in org.apache.commons.proxy.provider.remoting.RmiProvider", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-11112", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/issues/2666", + "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-11112", + "https://security.netapp.com/advisory/ntap-20200403-0002", + "https://security.netapp.com/advisory/ntap-20200403-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-11112", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-31T05:15:13.07Z", + "LastModifiedDate": "2026-06-17T02:49:04.457Z" + }, + { + "VulnerabilityID": "CVE-2020-11113", + "VendorIDs": [ + "GHSA-9vvp-fxw6-jcxr" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-11113", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:981c3175927a5c7b4142b7195c69a70d312b411e204b571982a6f6dcf2249d93", + "Title": "jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-11113", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88", + "https://github.com/FasterXML/jackson-databind/commit/e2ba12d5d60715d95105e3e790fc234cfb59893d", + "https://github.com/FasterXML/jackson-databind/issues/2670", + "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-11113", + "https://security.netapp.com/advisory/ntap-20200403-0002", + "https://security.netapp.com/advisory/ntap-20200403-0002/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-11113", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-03-31T05:15:13.117Z", + "LastModifiedDate": "2026-06-17T02:49:04.737Z" + }, + { + "VulnerabilityID": "CVE-2020-11619", + "VendorIDs": [ + "GHSA-27xj-rqx5-2255" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-11619", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:9baef14024e77ee9dea2eaf3268733b8810c118ed1a9586880bd85471054e557", + "Title": "jackson-databind: Serialization gadgets in org.springframework:spring-aop", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-11619", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/issues/2680", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-11619", + "https://security.netapp.com/advisory/ntap-20200511-0004", + "https://security.netapp.com/advisory/ntap-20200511-0004/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-11619", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2020-04-07T23:15:12.077Z", + "LastModifiedDate": "2026-06-17T02:50:29.94Z" + }, + { + "VulnerabilityID": "CVE-2020-11620", + "VendorIDs": [ + "GHSA-h4rc-386g-6m85" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-11620", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:a30864d8f8e4acd3dd0e76dca21cbcef4a5534398d34c3221b3b8d6d11afde03", + "Title": "jackson-databind: Serialization gadgets in commons-jelly:commons-jelly", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-11620", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88", + "https://github.com/FasterXML/jackson-databind/commit/77040d85e3eb6710508e6445640ae1a3d5e60c22", + "https://github.com/FasterXML/jackson-databind/issues/2682", + "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-11620", + "https://security.netapp.com/advisory/ntap-20200511-0004", + "https://security.netapp.com/advisory/ntap-20200511-0004/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-11620", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html" + ], + "PublishedDate": "2020-04-07T23:15:12.14Z", + "LastModifiedDate": "2026-06-17T02:50:30.1Z" + }, + { + "VulnerabilityID": "CVE-2020-14060", + "VendorIDs": [ + "GHSA-j823-4qch-3rgm" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-14060", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:1fd4ef5625f6bd87d849aa8740393d9d214c7a7be829727030281d9da4cf862a", + "Title": "jackson-databind: serialization in oadd.org.apache.xalan.lib.sql.JNDIConnectionPool", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-14060", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88", + "https://github.com/FasterXML/jackson-databind/commit/ac7232e3f9004bdb4f11dcb5bc6c1fadf074f5f7", + "https://github.com/FasterXML/jackson-databind/commit/d1c67a0396e84c08d0558fbb843b5bd1f26e1921", + "https://github.com/FasterXML/jackson-databind/issues/2688", + "https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-14060", + "https://security.netapp.com/advisory/ntap-20200702-0003", + "https://security.netapp.com/advisory/ntap-20200702-0003/", + "https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-14060", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-06-14T21:15:09.817Z", + "LastModifiedDate": "2026-06-17T02:54:10.143Z" + }, + { + "VulnerabilityID": "CVE-2020-14061", + "VendorIDs": [ + "GHSA-c2q3-4qrh-fm48" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-14061", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:478dad9e5f41ac83f6aa68402539d3e2cba8634ea2346d9ade3874fa843036c2", + "Title": "jackson-databind: serialization in weblogic/oracle-aqjms", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-14061", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/5c8642aeae9c756b438ab7637c90ef3c77966e6e", + "https://github.com/FasterXML/jackson-databind/issues/2698", + "https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-14061", + "https://security.netapp.com/advisory/ntap-20200702-0003", + "https://security.netapp.com/advisory/ntap-20200702-0003/", + "https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-14061", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-06-14T20:15:10.027Z", + "LastModifiedDate": "2026-06-17T02:54:10.29Z" + }, + { + "VulnerabilityID": "CVE-2020-14062", + "VendorIDs": [ + "GHSA-c265-37vj-cwcc" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-14062", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:0f153799b6b1b8697054afdd2ab1d641e574601878063e72211499354a9b81d0", + "Title": "jackson-databind: serialization in com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-14062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/840eae2ca81c597a0010b2126f32dce17d384b70", + "https://github.com/FasterXML/jackson-databind/commit/99001cdb6807b5c7b170ec6a9092ecbb618ae79c", + "https://github.com/FasterXML/jackson-databind/issues/2704", + "https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-14062", + "https://security.netapp.com/advisory/ntap-20200702-0003", + "https://security.netapp.com/advisory/ntap-20200702-0003/", + "https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-14062", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-06-14T20:15:10.167Z", + "LastModifiedDate": "2026-06-17T02:54:10.503Z" + }, + { + "VulnerabilityID": "CVE-2020-14195", + "VendorIDs": [ + "GHSA-mc6h-4qgp-37qh" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-14195", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:f5e6fb149464245c4bb4e021c1559a751c615893affefafdc8577d2e3df07968", + "Title": "jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-14195", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88", + "https://github.com/FasterXML/jackson-databind/commit/f6d9c664f6d481703138319f6a0f1fdbddb3a259", + "https://github.com/FasterXML/jackson-databind/issues/2765", + "https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-14195", + "https://security.netapp.com/advisory/ntap-20200702-0003", + "https://security.netapp.com/advisory/ntap-20200702-0003/", + "https://ubuntu.com/security/notices/USN-4813-1", + "https://www.cve.org/CVERecord?id=CVE-2020-14195", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-06-16T16:15:11.107Z", + "LastModifiedDate": "2026-06-17T02:54:22.23Z" + }, + { + "VulnerabilityID": "CVE-2020-24616", + "VendorIDs": [ + "GHSA-h3cw-g4mq-c5x2" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-24616", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:29c19cff7a0c35389d9fb82eba72768dbfb95a90cee547ce8d350dffa0360885", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-24616", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/3d97153944f7de9c19c1b3637b33d3cf1fbbe4d7", + "https://github.com/FasterXML/jackson-databind/issues/2814", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-24616", + "https://security.netapp.com/advisory/ntap-20200904-0006", + "https://security.netapp.com/advisory/ntap-20200904-0006/", + "https://www.cve.org/CVERecord?id=CVE-2020-24616", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-08-25T18:15:11.133Z", + "LastModifiedDate": "2026-06-17T03:05:51.877Z" + }, + { + "VulnerabilityID": "CVE-2020-24750", + "VendorIDs": [ + "GHSA-qjw2-hr98-qgfh" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.6.7.5, 2.9.10.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-24750", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:ad37951b9ef3e6d05e9773c84942695193971a85f384de8fd6ab6b134f032f83", + "Title": "jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-24750", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/2118e71325486c68f089a9761c9d8a11b4ddd1cb", + "https://github.com/FasterXML/jackson-databind/commit/6cc9f1a1af323cd156f5668a47e43bab324ae16f", + "https://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86b", + "https://github.com/FasterXML/jackson-databind/issues/2798", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-24750", + "https://security.netapp.com/advisory/ntap-20201009-0003", + "https://security.netapp.com/advisory/ntap-20201009-0003/", + "https://www.cve.org/CVERecord?id=CVE-2020-24750", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-09-17T19:15:13.58Z", + "LastModifiedDate": "2026-06-17T03:06:03.063Z" + }, + { + "VulnerabilityID": "CVE-2020-25649", + "VendorIDs": [ + "GHSA-288c-cq4h-88gq" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.6.7.4, 2.9.10.7, 2.10.5.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-25649", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:d2538802c625d4e8ba79c16215079796b91077daaa5b8b6bacb4ce5177bd6acb", + "Title": "jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)", + "Description": "A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-611" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-25649", + "https://bugzilla.redhat.com/show_bug.cgi?id=1887664", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/3d932709abd0b5390efe67451653fc9efa9db677", + "https://github.com/FasterXML/jackson-databind/commit/612f971b78c60202e9cd75a299050c8f2d724a59", + "https://github.com/FasterXML/jackson-databind/commit/612f971b78c60202e9cd75a299050c8f2d724a59%20%28jackson-databind-2.11.0.rc1%29", + "https://github.com/FasterXML/jackson-databind/issues/2589", + "https://lists.apache.org/thread.html/r011d1430e8f40dff9550c3bc5d0f48b14c01ba8aecabd91d5e495386@%3Ccommits.turbine.apache.org%3E", + "https://lists.apache.org/thread.html/r024b7bda9c43c5560d81238748775c5ecfe01b57280f90df1f773949@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/r04529cedaca40c2ff90af4880493f9c88a8ebf4d1d6c861d23108a5a@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r0881e23bd9034c8f51fdccdc8f4d085ba985dcd738f8520569ca5c3d@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/r0b8dc3acd4503e4ecb6fbd6ea7d95f59941168d8452ac0ab1d1d96bb@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r1b7ed0c4b6c4301d4dfd6fdbc5581b0a789d3240cab55d766f33c6c6@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r2882fc1f3032cd7be66e28787f04ec6f1874ac68d47e310e30ff7eb1@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r2b6ddb3a4f4cd11d8f6305011e1b7438ba813511f2e3ab3180c7ffda@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r2eb66c182853c69ecfb52f63d3dec09495e9b65be829fd889a081ae1@%3Cdev.hive.apache.org%3E", + "https://lists.apache.org/thread.html/r2f5c5479f99398ef344b7ebd4d90bc3316236c45d0f3bc42090efcd7@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/r31f4ee7d561d56a0c2c2c6eb1d6ce3e05917ff9654fdbfec05dc2b83@%3Ccommits.servicecomb.apache.org%3E", + "https://lists.apache.org/thread.html/r3e6ae311842de4e64c5d560a475b7f9cc7e0a9a8649363c6cf7537eb@%3Ccommits.karaf.apache.org%3E", + "https://lists.apache.org/thread.html/r407538adec3185dd35a05c9a26ae2f74425b15132470cf540f41d85b@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/r45e7350dfc92bb192f3f88e9971c11ab2be0953cc375be3dda5170bd@%3Cissues.flink.apache.org%3E", + "https://lists.apache.org/thread.html/r5b130fe668503c4b7e2caf1b16f86b7f2070fd1b7ef8f26195a2ffbd@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/r5f8a1608d758936bd6bbc5eed980777437b611537bf6fff40663fc71@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r605764e05e201db33b3e9c2e66ff620658f07ad74f296abe483f7042@%3Creviews.iotdb.apache.org%3E", + "https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r63c87aab97155f3f3cbe11d030c4a184ea0de440ee714977db02e956@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r68d029ee74ab0f3b0569d0c05f5688cb45dd3abe96a6534735252805@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r6a4f3ef6edfed2e0884269d84798f766779bbbc1005f7884e0800d61@%3Cdev.knox.apache.org%3E", + "https://lists.apache.org/thread.html/r6a6df5647583541e3cb71c75141008802f7025cee1c430d4ed78f4cc@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cusers.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r6cbd599b80e787f02ff7a1391d9278a03f37d6a6f4f943f0f01a62fb@%3Creviews.iotdb.apache.org%3E", + "https://lists.apache.org/thread.html/r6e3d4f7991542119a4ca6330271d7fbf7b9fb3abab24ada82ddf1ee4@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r73bef1bb601a9f093f915f8075eb49fcca51efade57b817afd5def07@%3Ccommits.iotdb.apache.org%3E", + "https://lists.apache.org/thread.html/r765283e145049df9b8998f14dcd444345555aae02b1610cfb3188bf8@%3Cnotifications.iotdb.apache.org%3E", + "https://lists.apache.org/thread.html/r78d53a0a269c18394daf5940105dc8c7f9a2399503c2e78be20abe7e@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r7cb5b4b3e4bd41a8042e5725b7285877a17bcbf07f4eb3f7b316af60@%3Creviews.iotdb.apache.org%3E", + "https://lists.apache.org/thread.html/r86c78bf7656fdb2dab69cbf17f3d7492300f771025f1a3a65d5e5ce5@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r8764bb835bcb8e311c882ff91dd3949c9824e905e880930be56f6ba3@%3Cuser.spark.apache.org%3E", + "https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cusers.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r8ae961c80930e2717c75025414ce48a432cea1137c02f648b1fb9524@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/r900d4408c4189b376d1ec580ea7740ea6f8710dc2f0b7e9c9eeb5ae0@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r90d1e97b0a743cf697d89a792a9b669909cc5a1692d1e0083a22e66c@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r91722ecfba688b0c565675f8bf380269fde8ec62b54d6161db544c22@%3Ccommits.karaf.apache.org%3E", + "https://lists.apache.org/thread.html/r94c7e86e546120f157264ba5ba61fd29b3a8d530ed325a9b4fa334d7@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r95a297eb5fd1f2d3a2281f15340e2413f952e9d5503296c3adc7201a@%3Ccommits.tomee.apache.org%3E", + "https://lists.apache.org/thread.html/r98bfe3b90ea9408f12c4b447edcb5638703d80bc782430aa0c210a54@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ra1157e57a01d25e36b0dc17959ace758fc21ba36746de29ba1d8b130@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/ra409f798a1e5a6652b7097429b388650ccd65fd958cee0b6f69bba00@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/ra95faf968f3463acb3f31a6fbec31453fc5045325f99f396961886d3@%3Cissues.flink.apache.org%3E", + "https://lists.apache.org/thread.html/raf13235de6df1d47a717199e1ecd700dff3236632f5c9a1488d9845b@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rb674520b9f6c808c1bf263b1369e14048ec3243615f35cfd24e33604@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rc15e90bbef196a5c6c01659e015249d6c9a73581ca9afb8aeecf00d2@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rc82ff47853289e9cd17f5cfbb053c04cafc75ee32e3d7223963f83bb@%3Cdev.knox.apache.org%3E", + "https://lists.apache.org/thread.html/rc88f2fa2b7bd6443921727aeee7704a1fb02433e722e2abf677e0d3d@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rc959cdb57c4fe198316130ff4a5ecbf9d680e356032ff2e9f4f05d54@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rd317f15a675d114dbf5b488d27eeb2467b4424356b16116eb18a652d@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rd57c7582adc90e233f23f3727db3df9115b27a823b92374f11453f34@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/rd6f6bf848c2d47fa4a85c27d011d948778b8f7e58ba495968435a0b3@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rdca8711bb7aa5d47a44682606cd0ea3497e2e922f22b7ee83e81e6c1@%3Cissues.hive.apache.org%3E", + "https://lists.apache.org/thread.html/rdf9a34726482222c90d50ae1b9847881de67dde8cfde4999633d2cdc@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/re16f81d3ad49a93dd2f0cba9f8fc88e5fb89f30bf9a2ad7b6f3e69c1@%3Ccommits.karaf.apache.org%3E", + "https://lists.apache.org/thread.html/re96dc7a13e13e56190a5d80f9e5440a0d0c83aeec6467b562fbf2dca@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rf1809a1374041a969d77afab21fc38925de066bc97e86157d3ac3402@%3Ccommits.karaf.apache.org%3E", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6X2UT4X6M7DLQYBOOHMXBWGYJ65RL2CT", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6X2UT4X6M7DLQYBOOHMXBWGYJ65RL2CT/", + "https://nvd.nist.gov/vuln/detail/CVE-2020-25649", + "https://security.netapp.com/advisory/ntap-20210108-0007", + "https://security.netapp.com/advisory/ntap-20210108-0007/", + "https://www.cve.org/CVERecord?id=CVE-2020-25649", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-12-03T17:15:12.503Z", + "LastModifiedDate": "2026-06-17T03:07:02.897Z" + }, + { + "VulnerabilityID": "CVE-2020-35490", + "VendorIDs": [ + "GHSA-wh8g-3j2c-rqj5" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-35490", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:023de6c2022dc3460e58e0e873249d7421525eb2bc5328c245925d533a133a6b", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-35490", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/41b8bdb5ccc1d8edb71acf1c8234da235a24249d", + "https://github.com/FasterXML/jackson-databind/issues/2986", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-35490", + "https://security.netapp.com/advisory/ntap-20210122-0005", + "https://security.netapp.com/advisory/ntap-20210122-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-35490", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-12-17T19:15:14.417Z", + "LastModifiedDate": "2026-06-17T03:13:47.92Z" + }, + { + "VulnerabilityID": "CVE-2020-35491", + "VendorIDs": [ + "GHSA-r3gr-cxrf-hg25" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-35491", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:c9c281e74dc684c0a476bfb11198dc072cbec2d3105958981e6395e6baf91067", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-35491", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/41b8bdb5ccc1d8edb71acf1c8234da235a24249d", + "https://github.com/FasterXML/jackson-databind/issues/2986", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-35491", + "https://security.netapp.com/advisory/ntap-20210122-0005", + "https://security.netapp.com/advisory/ntap-20210122-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-35491", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-12-17T19:15:14.48Z", + "LastModifiedDate": "2026-06-17T03:13:48.087Z" + }, + { + "VulnerabilityID": "CVE-2020-35728", + "VendorIDs": [ + "GHSA-5r5r-6hpj-8gg9" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-35728", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:98b6f39e587bd22dd8a412de793a62d96acb2db97ae2a5f7081adef302c9cfde", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-35728", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/1ca0388c2fb37ac6a06f1c188ae89c41e3e15e84", + "https://github.com/FasterXML/jackson-databind/issues/2999", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://nvd.nist.gov/vuln/detail/CVE-2020-35728", + "https://security.netapp.com/advisory/ntap-20210129-0007", + "https://security.netapp.com/advisory/ntap-20210129-0007/", + "https://www.cve.org/CVERecord?id=CVE-2020-35728", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-12-27T05:15:11.59Z", + "LastModifiedDate": "2026-06-17T03:14:11.917Z" + }, + { + "VulnerabilityID": "CVE-2020-36179", + "VendorIDs": [ + "GHSA-9gph-22xh-8x98" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8, 2.6.7.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36179", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:9a52d83e171fa11a5e6786b19b6b152c1395cc8ded6a5a888df9a64b341755a5", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36179", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b", + "https://github.com/FasterXML/jackson-databind/issues/3004", + "https://lists.apache.org/thread.html/rc255f41d9a61d3dc79a51fb5c713de4ae10e71e3673feeb0b180b436@%3Cissues.spark.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36179", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36179", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-07T00:15:14.85Z", + "LastModifiedDate": "2026-06-17T03:14:54.74Z" + }, + { + "VulnerabilityID": "CVE-2020-36180", + "VendorIDs": [ + "GHSA-8c4j-34r4-xr8g" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8, 2.6.7.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36180", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:75ae94165829a9c888128f111dd520405a087e666e91790a5998dbe9839fbc11", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36180", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b", + "https://github.com/FasterXML/jackson-databind/issues/3004", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36180", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36180", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-07T00:15:14.913Z", + "LastModifiedDate": "2026-06-17T03:14:55.067Z" + }, + { + "VulnerabilityID": "CVE-2020-36181", + "VendorIDs": [ + "GHSA-cvm9-fjm9-3572" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8, 2.6.7.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36181", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:da7b15a901557e47507077b1631af365228b3bbcb61d14c94194a9288609e3a8", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36181", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b", + "https://github.com/FasterXML/jackson-databind/issues/3004", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36181", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36181", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-06T23:15:12.957Z", + "LastModifiedDate": "2026-06-17T03:14:55.41Z" + }, + { + "VulnerabilityID": "CVE-2020-36182", + "VendorIDs": [ + "GHSA-89qr-369f-5m5x" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8, 2.6.7.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36182", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:84e4af8eca851e838c90cb15ee6240d95588de1140ece45a53f926e3374d7def", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36182", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b", + "https://github.com/FasterXML/jackson-databind/issues/3004", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36182", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36182", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-07T00:15:14.96Z", + "LastModifiedDate": "2026-06-17T03:14:55.723Z" + }, + { + "VulnerabilityID": "CVE-2020-36183", + "VendorIDs": [ + "GHSA-9m6f-7xcq-8vf8" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8, 2.6.7.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36183", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:43db469a4c8ec30923af75fd603539310414353a49ab3bc975f24e75c367e403", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36183", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/12e23c962ffb4cf1857c5461d72ae54cc8008f29", + "https://github.com/FasterXML/jackson-databind/issues/3003", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36183", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36183", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-07T00:15:15.023Z", + "LastModifiedDate": "2026-06-17T03:14:56.05Z" + }, + { + "VulnerabilityID": "CVE-2020-36184", + "VendorIDs": [ + "GHSA-m6x4-97wx-4q27" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36184", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:7102750277b4d1f800ca6a308b2d2212409839150a183aedf2cbf6cd32be63d8", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36184", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/567194c53ae91f0a14dc27239afb739b1c10448a", + "https://github.com/FasterXML/jackson-databind/issues/2998", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36184", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36184", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-06T23:15:13.017Z", + "LastModifiedDate": "2026-06-17T03:14:56.223Z" + }, + { + "VulnerabilityID": "CVE-2020-36185", + "VendorIDs": [ + "GHSA-8w26-6f25-cm9x" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36185", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:85f1ca46f3fc352767774883050c8d6d705771ccec59a5c2419b88673f3ac55a", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36185", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/567194c53ae91f0a14dc27239afb739b1c10448a", + "https://github.com/FasterXML/jackson-databind/issues/2998", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36185", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36185", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-06T23:15:13.077Z", + "LastModifiedDate": "2026-06-17T03:14:56.54Z" + }, + { + "VulnerabilityID": "CVE-2020-36186", + "VendorIDs": [ + "GHSA-v585-23hc-c647" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36186", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:2426fb1045f889bf66f9f2e9cf8a2ab22eb23c4802d2554f2b7e6349ad2168da", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36186", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1", + "https://github.com/FasterXML/jackson-databind/issues/2997", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36186", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36186", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-06T23:15:13.123Z", + "LastModifiedDate": "2026-06-17T03:14:56.72Z" + }, + { + "VulnerabilityID": "CVE-2020-36187", + "VendorIDs": [ + "GHSA-r695-7vr9-jgc2" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36187", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:e1364e1ed7390eadd58c2212e8cb2d8ae3c47f00e92d0932fccbf8b976e15f8f", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36187", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1", + "https://github.com/FasterXML/jackson-databind/issues/2997", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36187", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36187", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-06T23:15:13.17Z", + "LastModifiedDate": "2026-06-17T03:14:57.653Z" + }, + { + "VulnerabilityID": "CVE-2020-36188", + "VendorIDs": [ + "GHSA-f9xh-2qgp-cq57" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8, 2.6.7.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36188", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:d8305bc9a2bed398154595e8f271d03fc6d1c81594c22baa11e72e5aef42e7f3", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36188", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4", + "https://github.com/FasterXML/jackson-databind/issues/2996", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36188", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36188", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-06T23:15:13.233Z", + "LastModifiedDate": "2026-06-17T03:14:57.817Z" + }, + { + "VulnerabilityID": "CVE-2020-36189", + "VendorIDs": [ + "GHSA-vfqx-33qm-g869" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.8, 2.6.7.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36189", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:36903a464319ea6abfb223e2f7045b5ba148855c3329d4a0f581f112b4220bdc", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource", + "Description": "FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-36189", + "https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4", + "https://github.com/FasterXML/jackson-databind/issues/2996", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36189", + "https://security.netapp.com/advisory/ntap-20210205-0005", + "https://security.netapp.com/advisory/ntap-20210205-0005/", + "https://www.cve.org/CVERecord?id=CVE-2020-36189", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2021-01-06T23:15:13.28Z", + "LastModifiedDate": "2026-06-17T03:14:57.987Z" + }, + { + "VulnerabilityID": "CVE-2020-36518", + "VendorIDs": [ + "GHSA-57j2-w4cx-62h2" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.13.2.1, 2.12.6.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-36518", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:584b932522d3937b84b847f959c8a065555757a5115d8fbe326f7d0f1205a730", + "Title": "jackson-databind: denial of service via a large depth of nested objects", + "Description": "jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "redhat": 2, + "rocky": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:2312", + "https://access.redhat.com/errata/RHSA-2024:3061", + "https://access.redhat.com/security/cve/CVE-2020-36518", + "https://bugzilla.redhat.com/2064698", + "https://bugzilla.redhat.com/show_bug.cgi?id=2064698", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36518", + "https://errata.almalinux.org/9/ALSA-2023-2312.html", + "https://errata.rockylinux.org/RLSA-2024:3061", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/0a8157c6ca478b1bc7be4ba7dccdb3863275f0de", + "https://github.com/FasterXML/jackson-databind/commit/3cc52f82ecf943e06c1d7c3b078e405fb3923d2b", + "https://github.com/FasterXML/jackson-databind/commit/8238ab41d0350fb915797c89d46777b4496b74fd", + "https://github.com/FasterXML/jackson-databind/commit/b3587924ee5d8695942f364d0d404d48d0ea6126", + "https://github.com/FasterXML/jackson-databind/commit/fcfc4998ec23f0b1f7f8a9521c2b317b6c25892b", + "https://github.com/FasterXML/jackson-databind/issues/2816", + "https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12", + "https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.13", + "https://github.com/advisories/GHSA-57j2-w4cx-62h2", + "https://linux.oracle.com/cve/CVE-2020-36518.html", + "https://linux.oracle.com/errata/ELSA-2024-3061.html", + "https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html", + "https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-36518", + "https://security.netapp.com/advisory/ntap-20220506-0004", + "https://security.netapp.com/advisory/ntap-20220506-0004/", + "https://www.cve.org/CVERecord?id=CVE-2020-36518", + "https://www.debian.org/security/2022/dsa-5283", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-03-11T07:15:07.8Z", + "LastModifiedDate": "2026-06-17T03:15:38.263Z" + }, + { + "VulnerabilityID": "CVE-2021-20190", + "VendorIDs": [ + "GHSA-5949-rw7g-wx7w" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.9.10.7, 2.6.7.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-20190", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:4d6beba07e7e154922802a4c55451900ed7e3dc656aa93c011707a3ec02f8522", + "Title": "jackson-databind: mishandles the interaction between serialization gadgets and typing, related to javax.swing", + "Description": "A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:C", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 8.3, + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2021-20190", + "https://bugzilla.redhat.com/show_bug.cgi?id=1916633", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88", + "https://github.com/FasterXML/jackson-databind/commit/7dbf51bf78d157098074a20bd9da39bd48c18e4a", + "https://github.com/FasterXML/jackson-databind/issues/2854", + "https://github.com/advisories/GHSA-5949-rw7g-wx7w", + "https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a@%3Ccommits.nifi.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-20190", + "https://security.netapp.com/advisory/ntap-20210219-0008", + "https://security.netapp.com/advisory/ntap-20210219-0008/", + "https://www.cve.org/CVERecord?id=CVE-2021-20190", + "https://www.oracle.com//security-alerts/cpujul2021.html" + ], + "PublishedDate": "2021-01-19T17:15:13.427Z", + "LastModifiedDate": "2026-07-24T14:27:51.33Z" + }, + { + "VulnerabilityID": "CVE-2022-42003", + "VendorIDs": [ + "GHSA-jjjh-jjxp-wpff" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.12.7.1, 2.13.4.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-42003", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:33f10e3c955a9011eae4b16a64518342e0e62da4febdc6669480ab6a3deae0aa", + "Title": "jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS", + "Description": "In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-42003", + "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51020", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/blob/2.13/release-notes/VERSION-2.x", + "https://github.com/FasterXML/jackson-databind/commit/0e37a39502439ecbaa1a5b5188387c01bf7f7fa1", + "https://github.com/FasterXML/jackson-databind/commit/2c4a601c626f7790cad9d3c322d244e182838288", + "https://github.com/FasterXML/jackson-databind/commit/7ba9ac5b87a9d6ac0d2815158ecbeb315ad4dcdc", + "https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea", + "https://github.com/FasterXML/jackson-databind/commit/d499f2e7bbc5ebd63af11e1f5cf1989fa323aa45", + "https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33", + "https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33%20%28jackson-databind-2.14.0-rc1%29", + "https://github.com/FasterXML/jackson-databind/commits/jackson-databind-2.4.0-rc1?after=75b97b8519f0d50c62523ad85170d80a197a2c86+174&branch=jackson-databind-2.4.0-rc1&qualified_name=refs%2Ftags%2Fjackson-databind-2.4.0-rc1", + "https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.13.4.1...jackson-databind-2.13.4.2", + "https://github.com/FasterXML/jackson-databind/issues/3590", + "https://github.com/FasterXML/jackson-databind/issues/3627", + "https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-42003", + "https://security.gentoo.org/glsa/202210-21", + "https://security.netapp.com/advisory/ntap-20221124-0004", + "https://security.netapp.com/advisory/ntap-20221124-0004/", + "https://www.cve.org/CVERecord?id=CVE-2022-42003", + "https://www.debian.org/security/2022/dsa-5283" + ], + "PublishedDate": "2022-10-02T05:15:09.07Z", + "LastModifiedDate": "2026-06-17T05:04:13.767Z" + }, + { + "VulnerabilityID": "CVE-2022-42004", + "VendorIDs": [ + "GHSA-rgv9-q543-rqg4" + ], + "PkgName": "com.fasterxml.jackson.core:jackson-databind", + "PkgPath": "usr/local/share/InterProScan/lib/jackson-databind-2.9.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8", + "UID": "c3cdf11f305c98df" + }, + "InstalledVersion": "2.9.8", + "FixedVersion": "2.12.7.1, 2.13.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-42004", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:5256fca4f80e8bfba07ec1adacd4d68bc2b597836df31965dc0a43f722788827", + "Title": "jackson-databind: use of deeply nested arrays", + "Description": "In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-42004", + "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490", + "https://github.com/FasterXML/jackson-databind", + "https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88", + "https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88%20%28jackson-databind-2.13.4%29", + "https://github.com/FasterXML/jackson-databind/commit/0e37a39502439ecbaa1a5b5188387c01bf7f7fa1", + "https://github.com/FasterXML/jackson-databind/commit/35de19e7144c4df8ab178b800ba86e80c3d84252", + "https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea", + "https://github.com/FasterXML/jackson-databind/issues/3582", + "https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-42004", + "https://security.gentoo.org/glsa/202210-21", + "https://security.netapp.com/advisory/ntap-20221118-0008", + "https://security.netapp.com/advisory/ntap-20221118-0008/", + "https://www.cve.org/CVERecord?id=CVE-2022-42004", + "https://www.debian.org/security/2022/dsa-5283" + ], + "PublishedDate": "2022-10-02T05:15:09.237Z", + "LastModifiedDate": "2026-06-17T05:04:13.9Z" + }, + { + "VulnerabilityID": "CVE-2021-42392", + "VendorIDs": [ + "GHSA-h376-j262-vhq6" + ], + "PkgName": "com.h2database:h2", + "PkgPath": "usr/local/share/InterProScan/lib/h2-1.4.199.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.h2database/h2@1.4.199", + "UID": "fa20d89f0498fa50" + }, + "InstalledVersion": "1.4.199", + "FixedVersion": "2.0.206", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-42392", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:590572b0b80ee423399a34749d553e22e0247f7d01326912955d3c900da8be36", + "Title": "h2: Remote Code Execution in Console", + "Description": "The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 4, + "redhat": 2, + "ubuntu": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 10, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2021-42392", + "https://github.com/h2database/h2database", + "https://github.com/h2database/h2database/releases/tag/version-2.0.206", + "https://github.com/h2database/h2database/security/advisories/GHSA-h376-j262-vhq6", + "https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console", + "https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/", + "https://lists.debian.org/debian-lts-announce/2022/02/msg00017.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-42392", + "https://security.netapp.com/advisory/ntap-20220119-0001", + "https://security.netapp.com/advisory/ntap-20220119-0001/", + "https://ubuntu.com/security/notices/USN-5365-1", + "https://ubuntu.com/security/notices/USN-6834-1", + "https://www.cve.org/CVERecord?id=CVE-2021-42392", + "https://www.debian.org/security/2022/dsa-5076", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.secpod.com/blog/log4shell-critical-remote-code-execution-vulnerability-in-h2database-console", + "https://www.secpod.com/blog/log4shell-critical-remote-code-execution-vulnerability-in-h2database-console/" + ], + "PublishedDate": "2022-01-10T14:10:23.643Z", + "LastModifiedDate": "2026-06-17T04:09:45.39Z" + }, + { + "VulnerabilityID": "CVE-2022-23221", + "VendorIDs": [ + "GHSA-45hx-wfhj-473x" + ], + "PkgName": "com.h2database:h2", + "PkgPath": "usr/local/share/InterProScan/lib/h2-1.4.199.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.h2database/h2@1.4.199", + "UID": "fa20d89f0498fa50" + }, + "InstalledVersion": "1.4.199", + "FixedVersion": "2.1.210", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23221", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:65a8accd7a2e6b1f4ffa1248ca83ec2a080ccf814e51754754fef0a9db3f65f8", + "Title": "h2: Loading of custom classes from remote servers through JNDI", + "Description": "H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-88" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 4, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 10, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "http://packetstormsecurity.com/files/165676/H2-Database-Console-Remote-Code-Execution.html", + "http://seclists.org/fulldisclosure/2022/Jan/39", + "https://access.redhat.com/security/cve/CVE-2022-23221", + "https://github.com/advisories/GHSA-45hx-wfhj-473x", + "https://github.com/h2database/h2database", + "https://github.com/h2database/h2database/releases/tag/version-2.1.210", + "https://github.com/h2database/h2database/security/advisories", + "https://lists.debian.org/debian-lts-announce/2022/02/msg00017.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23221", + "https://security.netapp.com/advisory/ntap-20230818-0011", + "https://security.netapp.com/advisory/ntap-20230818-0011/", + "https://twitter.com/d0nkey_man/status/1483824727936450564", + "https://ubuntu.com/security/notices/USN-5365-1", + "https://ubuntu.com/security/notices/USN-6834-1", + "https://www.cve.org/CVERecord?id=CVE-2022-23221", + "https://www.debian.org/security/2022/dsa-5076", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-01-19T17:15:09Z", + "LastModifiedDate": "2026-06-17T04:29:41.63Z" + }, + { + "VulnerabilityID": "CVE-2021-23463", + "VendorIDs": [ + "GHSA-7rpj-hg47-cx62" + ], + "PkgName": "com.h2database:h2", + "PkgPath": "usr/local/share/InterProScan/lib/h2-1.4.199.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.h2database/h2@1.4.199", + "UID": "fa20d89f0498fa50" + }, + "InstalledVersion": "1.4.199", + "FixedVersion": "2.0.202", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-23463", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:0c014724607f263b11e3d6a9e37f61518d4613651bf33d0ab3b0393c80b35ab0", + "Title": "h2database: XXE injection vulnerability", + "Description": "The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-611" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 4, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V2Score": 6.4, + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 6.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2021-23463", + "https://github.com/boris-unckel/h2database/commit/f9ad6aef2bfa59eba2b4d3e7c4c32d2cce8e8b05", + "https://github.com/h2database/h2database", + "https://github.com/h2database/h2database/commit/d83285fd2e48fb075780ee95badee6f5a15ea7f8%23diff-008c2e4462609982199cd83e7cf6f1d6b41296b516783f6752c44b9f15dc7bc3", + "https://github.com/h2database/h2database/issues/3195", + "https://github.com/h2database/h2database/pull/3199", + "https://github.com/h2database/h2database/pull/3199#issuecomment-1002830390", + "https://nvd.nist.gov/vuln/detail/CVE-2021-23463", + "https://security.netapp.com/advisory/ntap-20230818-0010", + "https://security.netapp.com/advisory/ntap-20230818-0010/", + "https://snyk.io/vuln/SNYK-JAVA-COMH2DATABASE-1769238", + "https://www.cve.org/CVERecord?id=CVE-2021-23463", + "https://www.oracle.com/security-alerts/cpuapr2022.html" + ], + "PublishedDate": "2021-12-10T20:15:07.917Z", + "LastModifiedDate": "2026-06-17T03:38:47.61Z" + }, + { + "VulnerabilityID": "CVE-2022-45868", + "VendorIDs": [ + "GHSA-22wj-vf5f-wrvj" + ], + "PkgName": "com.h2database:h2", + "PkgPath": "usr/local/share/InterProScan/lib/h2-1.4.199.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.h2database/h2@1.4.199", + "UID": "fa20d89f0498fa50" + }, + "InstalledVersion": "1.4.199", + "FixedVersion": "2.2.220", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-45868", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:959ba59b22baa4c445c8c15c6720ee174bd11f45fb158a7f685e8d77902644f8", + "Title": "The web-based admin console in H2 Database Engine before 2.2.220 can b ...", + "Description": "The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states \"This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that.\" Nonetheless, the issue was fixed in 2.2.220.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-312" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://github.com/advisories/GHSA-22wj-vf5f-wrvj", + "https://github.com/h2database/h2database", + "https://github.com/h2database/h2database/blob/96832bf5a97cdc0adc1f2066ed61c54990d66ab5/h2/src/main/org/h2/server/web/WebServer.java#L346-L347", + "https://github.com/h2database/h2database/commit/581ed18ff9d6b3761d851620ed88a3994a351a0d", + "https://github.com/h2database/h2database/issues/3686", + "https://github.com/h2database/h2database/pull/3833", + "https://github.com/h2database/h2database/releases/tag/version-2.2.220", + "https://nvd.nist.gov/vuln/detail/CVE-2022-45868", + "https://sites.google.com/sonatype.com/vulnerabilities/sonatype-2022-6243" + ], + "PublishedDate": "2022-11-23T21:15:11.36Z", + "LastModifiedDate": "2026-06-17T05:10:53.73Z" + }, + { + "VulnerabilityID": "CVE-2026-27830", + "VendorIDs": [ + "GHSA-5476-xc4j-rqcv" + ], + "PkgName": "com.mchange:c3p0", + "PkgPath": "usr/local/share/InterProScan/lib/c3p0-0.9.5.4.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.mchange/c3p0@0.9.5.4", + "UID": "d6d55a8bf55d6f91" + }, + "InstalledVersion": "0.9.5.4", + "FixedVersion": "0.12.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27830", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:1c44ed6eda3e93f5aa7dd8b4a8beaa8e1cc4cc877d32f5eddc8c0df569d1d8ef", + "Title": "c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects", + "Description": "c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map>`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application's `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0's main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0's `userOverridesAsString` hex-encoded serialized objects that include objects \"indirectly serialized\" via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0's vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across JNDI interfaces, represents a serious independent fragility. The `userOverridesAsString` property of c3p0 `ConnectionPoolDataSource` classes has been reimplemented to use a safe CSV-based format, rather than rely upon potentially dangerous Java object deserialization. c3p0-0.12.0+ and above depend upon mchange-commons-java 0.4.0+, which gates support for remote `factoryClassLocation` values by configuration parameters that default to restrictive values. c3p0 additionally enforces the new mchange-commons-java `com.mchange.v2.naming.nameGuardClassName` to prevent injection of unexpected, potentially remote JNDI names. There is no supported workaround for versions of c3p0 prior to 0.12.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-94", + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H", + "V40Score": 8.9 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:18054", + "https://access.redhat.com/errata/RHSA-2026:18055", + "https://access.redhat.com/errata/RHSA-2026:18059", + "https://access.redhat.com/errata/RHSA-2026:28385", + "https://access.redhat.com/errata/RHSA-2026:3890", + "https://access.redhat.com/errata/RHSA-2026:4285", + "https://access.redhat.com/security/cve/CVE-2026-27830", + "https://bugzilla.redhat.com/show_bug.cgi?id=2442908", + "https://github.com/swaldman/c3p0", + "https://github.com/swaldman/c3p0/commit/e14cbd8166e423e2e9a9d6f08b2add3433492d6e", + "https://github.com/swaldman/c3p0/security/advisories/GHSA-5476-xc4j-rqcv", + "https://mogwailabs.de/en/blog/2025/02/c3p0-you-little-rascal", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27830", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27830.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27830", + "https://www.mchange.com/projects/c3p0/#configuring_security", + "https://www.mchange.com/projects/c3p0/#security-note" + ], + "PublishedDate": "2026-02-26T01:16:24.583Z", + "LastModifiedDate": "2026-08-05T13:21:18.983Z" + }, + { + "VulnerabilityID": "CVE-2026-27727", + "VendorIDs": [ + "GHSA-m2cm-222f-qw44" + ], + "PkgName": "com.mchange:mchange-commons-java", + "PkgPath": "usr/local/share/InterProScan/lib/mchange-commons-java-0.2.15.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.mchange/mchange-commons-java@0.2.15", + "UID": "8eac267e271b41ed" + }, + "InstalledVersion": "0.2.15", + "FixedVersion": "0.4.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27727", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:cee209bef58cc0afea95b7c133bcbc5b15b23c36d03fbd270834bbd1ed64a34f", + "Title": "com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects", + "Description": "mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a maliciously crafted `jaxax.naming.Reference` or serialized object, they can provoke the download and execution of malicious code. Implementations of this functionality within the JDK were disabled by default behind a System property that defaults to `false`, `com.sun.jndi.ldap.object.trustURLCodebase`. However, since mchange-commons-java includes an independent implementation of JNDI derefencing, libraries (such as c3p0) that resolve references via that implementation could be provoked to download and execute malicious code even after the JDK was hardened. Mirroring the JDK patch, mchange-commons-java's JNDI functionality is gated by configuration parameters that default to restrictive values starting in version 0.4.0. No known workarounds are available. Versions prior to 0.4.0 should be avoided on application CLASSPATHs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 4, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H", + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 8.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:14873", + "https://access.redhat.com/errata/RHSA-2026:14874", + "https://access.redhat.com/errata/RHSA-2026:18054", + "https://access.redhat.com/errata/RHSA-2026:18055", + "https://access.redhat.com/errata/RHSA-2026:18059", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:3890", + "https://access.redhat.com/errata/RHSA-2026:4285", + "https://access.redhat.com/security/cve/CVE-2026-27727", + "https://bugzilla.redhat.com/show_bug.cgi?id=2442671", + "https://github.com/swaldman/mchange-commons-java", + "https://github.com/swaldman/mchange-commons-java/security/advisories/GHSA-m2cm-222f-qw44", + "https://mogwailabs.de/en/blog/2025/02/c3p0-you-little-rascal", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27727", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27727.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27727", + "https://www.mchange.com/projects/c3p0/#configuring_security", + "https://www.mchange.com/projects/c3p0/#security-note" + ], + "PublishedDate": "2026-02-25T17:25:39.91Z", + "LastModifiedDate": "2026-08-04T13:18:01.207Z" + }, + { + "VulnerabilityID": "CVE-2026-55153", + "VendorIDs": [ + "GHSA-h84g-69h7-mw6v" + ], + "PkgName": "com.mchange:mchange-commons-java", + "PkgPath": "usr/local/share/InterProScan/lib/mchange-commons-java-0.2.15.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/com.mchange/mchange-commons-java@0.2.15", + "UID": "8eac267e271b41ed" + }, + "InstalledVersion": "0.2.15", + "FixedVersion": "0.6.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55153", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:375aadfb951100d588905fe3d2ac3bdef3749eb7e3667ec11443916ca3be7a53", + "Title": "com.mchange/mchange-commons-java: mchange-commons-java: Remote code execution via JNDI injection", + "Description": "mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will construct objects of arbitrary classes and initialize \"JavaBean\"-style properties, which for certain classes enables JNDI injection and \"deserialization gadgets.\" Such initialization is unsafe for some classes: for example, setting the contentType property of a Swing JEditorPane to text/html and its text property to HTML containing a stylesheet will provoke an HTTP GET on an arbitrary URL, potentially from within a trusted security domain. The problem is aggravated by the library's ReferenceIndirector, through which malicious JNDI Reference objects can be smuggled in for dereferencing wherever an application reads a Java-serialized object. This has been resolved in version 0.6.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-470", + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-55153", + "https://github.com/swaldman/mchange-commons-java", + "https://github.com/swaldman/mchange-commons-java/security/advisories/GHSA-h84g-69h7-mw6v", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55153", + "https://www.cve.org/CVERecord?id=CVE-2026-55153" + ], + "PublishedDate": "2026-07-01T21:17:03.823Z", + "LastModifiedDate": "2026-07-06T15:16:39.837Z" + }, + { + "VulnerabilityID": "CVE-2024-47554", + "VendorIDs": [ + "GHSA-78wr-2p64-hpwj" + ], + "PkgName": "commons-io:commons-io", + "PkgPath": "usr/local/share/InterProScan/lib/commons-io-2.7.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/commons-io/commons-io@2.7", + "UID": "cef7318066751390" + }, + "InstalledVersion": "2.7", + "FixedVersion": "2.14.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-47554", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:8f98153f825e2d2bda90bdba16ea493fff6594c127c438b4f51c62a280ce0fd0", + "Title": "apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader", + "Description": "Uncontrolled Resource Consumption vulnerability in Apache Commons IO.\n\nThe org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.\n\n\nThis issue affects Apache Commons IO: from 2.0 before 2.14.0.\n\nUsers are recommended to upgrade to version 2.14.0 or later, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 2, + "cbl-mariner": 2, + "ghsa": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", + "V3Score": 4.3 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2024/10/03/2", + "https://access.redhat.com/security/cve/CVE-2024-47554", + "https://github.com/apache/commons-io", + "https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1", + "https://nvd.nist.gov/vuln/detail/CVE-2024-47554", + "https://security.netapp.com/advisory/ntap-20250131-0010", + "https://security.netapp.com/advisory/ntap-20250131-0010/", + "https://ubuntu.com/security/notices/USN-8191-1", + "https://www.cve.org/CVERecord?id=CVE-2024-47554" + ], + "PublishedDate": "2024-10-03T12:15:02.613Z", + "LastModifiedDate": "2026-06-17T07:57:17.887Z" + }, + { + "VulnerabilityID": "CVE-2019-17571", + "VendorIDs": [ + "GHSA-2qrg-x229-3v8q" + ], + "PkgName": "log4j:log4j", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/log4j-1.2.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/log4j/log4j@1.2.8", + "UID": "f7daaaf77b5b4a08" + }, + "InstalledVersion": "1.2.8", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-17571", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:290dfabe2ed38916d937b7701b3ed3102a7039d05ca3c41f76d4a44721699bc6", + "Title": "log4j: deserialization of untrusted data in SocketServer", + "Description": "Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "amazon": 2, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00022.html", + "https://access.redhat.com/security/cve/CVE-2019-17571", + "https://linux.oracle.com/cve/CVE-2019-17571.html", + "https://linux.oracle.com/errata/ELSA-2017-2423.html", + "https://lists.apache.org/thread.html/277b4b5c2b0e06a825ccec565fa65bd671f35a4d58e3e2ec5d0618e1@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/44491fb9cc19acc901f7cff34acb7376619f15638439416e3e14761c@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/479471e6debd608c837b9815b76eab24676657d4444fcfd5ef96d6e6@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/564f03b4e9511fcba29c68fc0299372dadbdb002718fa8edcc4325e4@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/6114ce566200d76e3cc45c521a62c2c5a4eac15738248f58a99f622c@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/752ec92cd1e334a639e79bfbd689a4ec2c6579ec5bb41b53ffdf358d@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/8ab32b4c9f1826f20add7c40be08909de9f58a89dc1de9c09953f5ac@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/eea03d504b36e8f870e8321d908e1def1addda16adda04327fe7c125@%3Cdev.logging.apache.org%3E", + "https://lists.apache.org/thread.html/r05755112a8c164abc1004bb44f198b1e3d8ca3d546a8f13ebd3aa05f@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r13d4b5c60ff63f3c4fab51d6ff266655be503b8a1884e2f2fab67c3a@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/r189aaeaad897f7d6b96f7c43a8ef2dfb9f6e9f8c1cc9ad182ce9b9ae@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r18f1c010b554a3a2d761e8ffffd8674fd4747bcbcf16c643d708318c@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r1b7734dfdfd938640f2f5fb6f4231a267145c71ed60cc7faa1cbac07@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/r26244f9f7d9a8a27a092eb0b2a0ca9395e88fcde8b5edaeca7ce569c@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe@%3Cusers.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r2756fd570b6709d55a61831ca028405bcb3e312175a60bc5d911c81f@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r2ce8d26154bea939536e6cf27ed02d3192bf5c5d04df885a80fe89b3@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r2ff63f210842a3c5e42f03a35d8f3a345134d073c80a04077341c211@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r3543ead2317dcd3306f69ee37b07dd383dbba6e2f47ff11eb55879ad@%3Cusers.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r356d57d6225f91fdc30f8b0a2bed229d1ece55e16e552878c5fa809a@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r3784834e80df2f284577a5596340fb84346c91a2dea6a073e65e3397@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r3a85514a518f3080ab1fc2652cfe122c2ccf67cfb32356acb1b08fe8@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/r3bf7b982dfa0779f8a71f843d2aa6b4184a53e6be7f149ee079387fd@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r3c575cabc7386e646fb12cb82b0b38ae5a6ade8a800f827107824495@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r3cf50d05ce8cec8c09392624b7bae750e7643dae60ef2438641ee015@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r3d666e4e8905157f3c046d31398b04f2bfd4519e31f266de108c6919@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r48d5019bd42e0770f7e5351e420a63a41ff1f16924942442c6aff6a8@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r48efc7cb5aeb4e1f67aaa06fb4b5479a5635d12f07d0b93fc2d08809@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r4ac89cbecd9e298ae9fafb5afda6fa77ac75c78d1ac957837e066c4e@%3Cuser.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r4b25538be50126194cc646836c718b1a4d8f71bd9c912af5b59134ad@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/r52a5129df402352adc34d052bab9234c8ef63596306506a89fdc7328@%3Cusers.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r594411f4bddebaf48a4c70266d0b7849e0d82bb72826f61b3a35bba7@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r5c084578b3e3b40bd903c9d9e525097421bcd88178e672f612102eb2@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r61590890edcc64140e0c606954b29a063c3d08a2b41d447256d51a78@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r6236b5f8646d48af8b66d5050f288304016840788e508c883356fe0e@%3Clog4j-user.logging.apache.org%3E", + "https://lists.apache.org/thread.html/r681b4432d0605f327b68b9f8a42662993e699d04614de4851c35ffd1@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/r696507338dd5f44efc23d98cafe30f217cf3ba78e77ed1324c7a5179@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r6aec6b8f70167fa325fb98b3b5c9ce0ffaed026e697b69b85ac24628@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r6b45a2fcc8e98ac93a179183dbb7f340027bdb8e3ab393418076b153@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/r6d34da5a0ca17ab08179a30c971446c7421af0e96f6d60867eabfc52@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r71e26f9c2d5826c6f95ad60f7d052d75e1e70b0d2dd853db6fc26d5f@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r746fbc3fc13aee292ae6851f7a5080f592fa3a67b983c6887cdb1fc5@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/r7a1acc95373105169bd44df710c2f462cad31fb805364d2958a5ee03@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r7bcdc710857725c311b856c0b82cee6207178af5dcde1bd43d289826@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r7f462c69d5ded4c0223e014d95a3496690423c5f6f05c09e2f2a407a@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd@%3Cusers.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r8418a0dff1729f19cf1024937e23a2db4c0f94f2794a423f5c10e8e7@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r8890b8f18f1de821595792b58b968a89692a255bc20d86d395270740@%3Ccommits.druid.apache.org%3E", + "https://lists.apache.org/thread.html/r8a1cfd4705258c106e488091fcec85f194c82f2bbde6bd151e201870@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/r8c392ca48bb7e50754e4bc05865e9731b23d568d18a520fe3d8c1f75@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/r8c6300245c0bcef095e9f07b48157e2c6471df0816db3408fcf1d748@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/r8d78a0fbb56d505461e29868d1026e98c402e6a568c13a6da67896a2@%3Cdev.jena.apache.org%3E", + "https://lists.apache.org/thread.html/r8e3f7da12bf5750b0a02e69a78a61073a2ac950eed7451ce70a65177@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r909b8e3a36913944d3b7bafe9635d4ca84f8f0e2cd146a1784f667c2@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r90c23eb8c82835fa82df85ae5e88c81fd9241e20a22971b0fb8f2c34@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r944183c871594fe9a555b8519a7c945bbcf6714d72461aa6c929028f@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r9a9e3b42cd5d1c4536a14ef04f75048dec8e2740ac6a138ea912177f@%3Cpluto-dev.portals.apache.org%3E", + "https://lists.apache.org/thread.html/r9d0d03f2e7d9e13c68b530f81d02b0fec33133edcf27330d8089fcfb@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/r9d2e28e71f91ba0b6f4114c8ecd96e2b1f7e0d06bdf8eb768c183aa9@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/r9dc2505651788ac668299774d9e7af4dc616be2f56fdc684d1170882@%3Cusers.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/r9fb3238cfc3222f2392ca6517353aadae18f76866157318ac562e706@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/ra18a903f785aed9403aea38bc6f36844a056283c00dcfc6936b6318c@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ra38785cfc0e7f17f8e24bebf775dd032c033fadcaea29e5bc9fffc60@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/ra54fa49be3e773d99ccc9c2a422311cf77e3ecd3b8594ee93043a6b1@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/ra9611a8431cb62369bce8909d7645597e1dd45c24b448836b1e54940@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/raedd12dc24412b3780432bf202a2618a21a727788543e5337a458ead@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/rb1b29aee737e1c37fe1d48528cb0febac4f5deed51f5412e6fdfe2bf@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/rb3c94619728c8f8c176d8e175e0a1086ca737ecdfcd5a2214bb768bc@%3Ccommits.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rbc45eb0f53fd6242af3e666c2189464f848a851d408289840cecc6e3@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rbd19de368abf0764e4383ec44d527bc9870176f488a494f09a40500d@%3Ccommon-dev.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/rbdf18e39428b5c80fc35113470198b1fe53b287a76a46b0f8780b5fd@%3Cdev.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rc17d8491beee51607693019857e41e769795366b85be00aa2f4b3159@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rc1eaed7f7d774d5d02f66e49baced31e04827a1293d61a70bd003ca7@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/rc628307962ae1b8cc2d21b8e4b7dd6d7755b2dd52fa56a151a27e4fd@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rca24a281000fb681d7e26e5c031a21eb4b0593a7735f781b53dae4e2@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/rcd71280585425dad7e232f239c5709e425efdd0d3de4a92f808a4767@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E", + "https://lists.apache.org/thread.html/rd3a9511eebab60e23f224841390a3f8cd5358cff605c5f7042171e47@%3Cdev.tinkerpop.apache.org%3E", + "https://lists.apache.org/thread.html/rd5dbeee4808c0f2b9b51479b50de3cc6adb1072c332a200d9107f13e@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/rd6254837403e8cbfc7018baa9be29705f3f06bd007c83708f9a97679@%3Cissues.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rd7805c1bf9388968508c6c8f84588773216e560055ddcc813d19f347@%3Ccommon-issues.hadoop.apache.org%3E", + "https://lists.apache.org/thread.html/rd882ab6b642fe59cbbe94dc02bd197342058208f482e57b537940a4b@%3Cpluto-dev.portals.apache.org%3E", + "https://lists.apache.org/thread.html/rda4849c6823dd3e83c7a356eb883180811d5c28359fe46865fd151c3@%3Cusers.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rdb7ddf28807e27c7801f6e56a0dfb31092d34c61bdd4fa2de9182119@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rdec0d8ac1f03e6905b0de2df1d5fcdb98b94556e4f6cccf7519fdb26@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/rdf2a0d94c3b5b523aeff7741ae71347415276062811b687f30ea6573@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/re36da78e4f3955ba6c1c373a2ab85a4deb215ca74b85fcd66142fea1@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/re8c21ed9dd218c217d242ffa90778428e446b082b5e1c29f567e8374@%3Cissues.activemq.apache.org%3E", + "https://lists.apache.org/thread.html/reaf6b996f74f12b4557bc221abe88f58270ac583942fa41293c61f94@%3Cpluto-scm.portals.apache.org%3E", + "https://lists.apache.org/thread.html/rec34b1cccf907898e7cb36051ffac3ccf1ea89d0b261a2a3b3fb267f@%3Ccommits.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf1b434e11834a4449cd7addb69ed0aef0923112b5938182b363a968c@%3Cnotifications.zookeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf2567488cfc9212b42e34c6393cfa1c14e30e4838b98dda84d71041f@%3Cdev.tika.apache.org%3E", + "https://lists.apache.org/thread.html/rf53eeefb7e7e524deaacb9f8671cbf01b8a253e865fb94e7656722c0@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.apache.org/thread.html/rf77f79699c8d7e430c14cf480f12ed1297e6e8cf2ed379a425941e80@%3Cpluto-dev.portals.apache.org%3E", + "https://lists.apache.org/thread.html/rf9c19bcc2f7a98a880fa3e3456c003d331812b55836b34ef648063c9@%3Cjira.kafka.apache.org%3E", + "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E", + "https://lists.apache.org/thread.html/rfdf65fa675c64a64459817344e0e6c44d51ee264beea6e5851fb60dc@%3Cissues.bookkeeper.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2020/01/msg00008.html", + "https://nvd.nist.gov/vuln/detail/CVE-2019-17571", + "https://security.netapp.com/advisory/ntap-20200110-0001", + "https://security.netapp.com/advisory/ntap-20200110-0001/", + "https://ubuntu.com/security/notices/USN-4495-1", + "https://ubuntu.com/security/notices/USN-5998-1", + "https://usn.ubuntu.com/4495-1", + "https://usn.ubuntu.com/4495-1/", + "https://www.cve.org/CVERecord?id=CVE-2019-17571", + "https://www.debian.org/security/2020/dsa-4686", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpuapr2020.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2019-12-20T17:15:11.893Z", + "LastModifiedDate": "2026-06-17T02:24:11.027Z" + }, + { + "VulnerabilityID": "CVE-2022-23305", + "VendorIDs": [ + "GHSA-65fg-84f6-3jq3" + ], + "PkgName": "log4j:log4j", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/log4j-1.2.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/log4j/log4j@1.2.8", + "UID": "f7daaaf77b5b4a08" + }, + "InstalledVersion": "1.2.8", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23305", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:941f904b687e32d1acd61d89a03e8d8c5db8440d76dfff0976b1e9b0e70d05c3", + "Title": "log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender", + "Description": "By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-89" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2022/01/18/4", + "https://access.redhat.com/security/cve/CVE-2022-23305", + "https://bugzilla.redhat.com/show_bug.cgi?id=2031667", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041949", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041967", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23302", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23305", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23307", + "https://errata.almalinux.org/8/ALSA-2022-0290.html", + "https://errata.rockylinux.org/RLSA-2022:0290", + "https://github.com/apache/logging-log4j1", + "https://linux.oracle.com/cve/CVE-2022-23305.html", + "https://linux.oracle.com/errata/ELSA-2022-9419.html", + "https://lists.apache.org/thread/pt6lh3pbsvxqlwlp4c5l798dv2hkc85y", + "https://logging.apache.org/log4j/1.2/index.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23305", + "https://security.netapp.com/advisory/ntap-20220217-0007", + "https://security.netapp.com/advisory/ntap-20220217-0007/", + "https://ubuntu.com/security/notices/USN-5998-1", + "https://ubuntu.com/security/notices/USN-7590-1", + "https://www.cve.org/CVERecord?id=CVE-2022-23305", + "https://www.openwall.com/lists/oss-security/2022/01/18/4", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-01-18T16:15:08.35Z", + "LastModifiedDate": "2026-06-17T04:29:50.293Z" + }, + { + "VulnerabilityID": "CVE-2022-23307", + "VendorIDs": [ + "GHSA-f7vh-qwp3-x37m" + ], + "PkgName": "log4j:log4j", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/log4j-1.2.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/log4j/log4j@1.2.8", + "UID": "f7daaaf77b5b4a08" + }, + "InstalledVersion": "1.2.8", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23307", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:4c2363a0b69708f636457002aeb83bcb23ca1767b03e4a56cd33f59f9459d81d", + "Title": "log4j: Unsafe deserialization flaw in Chainsaw log viewer", + "Description": "CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "ghsa": 4, + "nvd": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 9, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-23307", + "https://bugzilla.redhat.com/show_bug.cgi?id=2031667", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041949", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041967", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23302", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23305", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23307", + "https://errata.almalinux.org/8/ALSA-2022-0290.html", + "https://errata.rockylinux.org/RLSA-2022:0290", + "https://linux.oracle.com/cve/CVE-2022-23307.html", + "https://linux.oracle.com/errata/ELSA-2022-9419.html", + "https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh", + "https://logging.apache.org/log4j/1.2/index.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23307", + "https://ubuntu.com/security/notices/USN-5998-1", + "https://ubuntu.com/security/notices/USN-7590-1", + "https://www.cve.org/CVERecord?id=CVE-2022-23307", + "https://www.openwall.com/lists/oss-security/2022/01/18/5", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-01-18T16:15:08.403Z", + "LastModifiedDate": "2026-06-17T04:29:50.5Z" + }, + { + "VulnerabilityID": "CVE-2021-4104", + "VendorIDs": [ + "GHSA-fp5r-v3w9-4333" + ], + "PkgName": "log4j:log4j", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/log4j-1.2.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/log4j/log4j@1.2.8", + "UID": "f7daaaf77b5b4a08" + }, + "InstalledVersion": "1.2.8", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-4104", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:1dec24f46eae2a889ffb65ce83e4d3f3fad282b656be1e87a0cfeae6b60bbc1f", + "Title": "log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender", + "Description": "JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:S/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2022/01/18/3", + "https://access.redhat.com/security/cve/CVE-2021-4104", + "https://bugzilla.redhat.com/show_bug.cgi?id=2031667", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041949", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041967", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23302", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23305", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23307", + "https://errata.almalinux.org/8/ALSA-2022-0290.html", + "https://errata.rockylinux.org/RLSA-2022:0290", + "https://github.com/apache/logging-log4j2", + "https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126", + "https://github.com/apache/logging-log4j2/pull/608#issuecomment-991723301", + "https://linux.oracle.com/cve/CVE-2021-4104.html", + "https://linux.oracle.com/errata/ELSA-2022-9056.html", + "https://lists.apache.org/thread/0x4zvtq92yggdgvwfgsftqrj4xx5w0nx", + "https://nvd.nist.gov/vuln/detail/CVE-2021-4104", + "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0033", + "https://security.gentoo.org/glsa/202209-02", + "https://security.gentoo.org/glsa/202310-16", + "https://security.gentoo.org/glsa/202312-02", + "https://security.gentoo.org/glsa/202312-04", + "https://security.netapp.com/advisory/ntap-20211223-0007", + "https://security.netapp.com/advisory/ntap-20211223-0007/", + "https://ubuntu.com/security/notices/USN-5223-1", + "https://ubuntu.com/security/notices/USN-5223-2", + "https://www.cve.org/CVERecord?id=CVE-2021-4104", + "https://www.cve.org/CVERecord?id=CVE-2021-44228", + "https://www.kb.cert.org/vuls/id/930724", + "https://www.openwall.com/lists/oss-security/2021/12/13/1", + "https://www.openwall.com/lists/oss-security/2021/12/13/2", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-12-14T12:15:12.2Z", + "LastModifiedDate": "2026-06-17T04:19:02.513Z" + }, + { + "VulnerabilityID": "CVE-2022-23302", + "VendorIDs": [ + "GHSA-w9p3-5cr8-m3jj" + ], + "PkgName": "log4j:log4j", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/log4j-1.2.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/log4j/log4j@1.2.8", + "UID": "f7daaaf77b5b4a08" + }, + "InstalledVersion": "1.2.8", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23302", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:af981b1ce4dc8041d16b802f84d64a896c530a4554280c882d74415fcaeab41e", + "Title": "log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink", + "Description": "JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 1 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:S/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6, + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2022/01/18/3", + "https://access.redhat.com/security/cve/CVE-2022-23302", + "https://bugzilla.redhat.com/show_bug.cgi?id=2031667", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041949", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041959", + "https://bugzilla.redhat.com/show_bug.cgi?id=2041967", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4104", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23302", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23305", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23307", + "https://errata.almalinux.org/8/ALSA-2022-0290.html", + "https://errata.rockylinux.org/RLSA-2022:0290", + "https://github.com/apache/logging-log4j1", + "https://linux.oracle.com/cve/CVE-2022-23302.html", + "https://linux.oracle.com/errata/ELSA-2022-9419.html", + "https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w", + "https://logging.apache.org/log4j/1.2/index.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23302", + "https://security.netapp.com/advisory/ntap-20220217-0006", + "https://security.netapp.com/advisory/ntap-20220217-0006/", + "https://ubuntu.com/security/notices/USN-5998-1", + "https://ubuntu.com/security/notices/USN-7590-1", + "https://www.cve.org/CVERecord?id=CVE-2022-23302", + "https://www.openwall.com/lists/oss-security/2022/01/18/3", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.vicarius.io/vsociety/posts/cve-2022-23302-detect-log4j-1217-vulnerability", + "https://www.vicarius.io/vsociety/posts/cve-2022-23302-mitigate-log4j-1217-vulnerability" + ], + "PublishedDate": "2022-01-18T16:15:08.3Z", + "LastModifiedDate": "2026-06-17T04:29:49.853Z" + }, + { + "VulnerabilityID": "CVE-2023-26464", + "VendorIDs": [ + "GHSA-vp98-w2p3-mv35" + ], + "PkgName": "log4j:log4j", + "PkgPath": "usr/local/share/EMBOSS/jemboss/lib/axis/log4j-1.2.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/log4j/log4j@1.2.8", + "UID": "f7daaaf77b5b4a08" + }, + "InstalledVersion": "1.2.8", + "FixedVersion": "2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-26464", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:3c15c50629fb8aec1e15b79a3e8cb3bd59e735c43ba998dc6e85f75bd4c0c429", + "Title": "log4j1-socketappender: DoS via hashmap logging", + "Description": "** UNSUPPORTED WHEN ASSIGNED **\n\nWhen using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) \nhashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized.\n\nThis issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2023-26464", + "https://github.com/apache/logging-log4j2", + "https://lists.apache.org/thread/wkx6grrcjkh86crr49p4blc1v1nflj3t", + "https://nvd.nist.gov/vuln/detail/CVE-2023-26464", + "https://security.netapp.com/advisory/ntap-20230505-0008", + "https://security.netapp.com/advisory/ntap-20230505-0008/", + "https://www.cve.org/CVERecord?id=CVE-2023-26464", + "https://www.ibm.com/support/pages/security-bulletin-vulnerability-log4j-1216jar-affect-ibm-operations-analytics-log-analysis-cve-2023-26464" + ], + "PublishedDate": "2023-03-10T14:15:10.453Z", + "LastModifiedDate": "2026-06-17T05:43:23.487Z" + }, + { + "VulnerabilityID": "CVE-2023-26119", + "VendorIDs": [ + "GHSA-3xrr-7m6p-p7xh" + ], + "PkgName": "net.sourceforge.htmlunit:htmlunit", + "PkgPath": "usr/local/share/InterProScan/lib/htmlunit-2.40.0.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/net.sourceforge.htmlunit/htmlunit@2.40.0", + "UID": "2316a3be74396a2a" + }, + "InstalledVersion": "2.40.0", + "FixedVersion": "3.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-26119", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:6c46878ef859871dc3f01d077179c1ba11c35dd5263feff162fdfb88a735cd3e", + "Title": "HtmlUnit Code Injection vulnerability", + "Description": "Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 4 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://github.com/HtmlUnit/htmlunit", + "https://github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956b", + "https://nvd.nist.gov/vuln/detail/CVE-2023-26119", + "https://security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500", + "https://siebene.github.io/2022/12/30/HtmlUnit-RCE", + "https://siebene.github.io/2022/12/30/HtmlUnit-RCE/" + ], + "PublishedDate": "2023-04-03T05:15:07.863Z", + "LastModifiedDate": "2026-06-17T05:42:43.223Z" + }, + { + "VulnerabilityID": "CVE-2022-29546", + "VendorIDs": [ + "GHSA-6jmm-mp6w-4rrg" + ], + "PkgName": "net.sourceforge.htmlunit:neko-htmlunit", + "PkgPath": "usr/local/share/InterProScan/lib/neko-htmlunit-2.40.0.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/net.sourceforge.htmlunit/neko-htmlunit@2.40.0", + "UID": "b7eef148870902a7" + }, + "InstalledVersion": "2.40.0", + "FixedVersion": "2.61.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-29546", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:35ff78dd54dbb7a721da3d2a95d2258dcb42d872b24e2c3aeaf08a1ac67ddc74", + "Title": "OutOfMemory Exception by specifically crafted processing instruction in NekoHtml Parser", + "Description": "HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption. This is similar to CVE-2022-28366 but affects a much later version of the product.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3, + "nvd": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/HtmlUnit/htmlunit-neko", + "https://github.com/HtmlUnit/htmlunit-neko/commit/9d2aecd69223469e40c12ca3edddda09009110cc", + "https://github.com/HtmlUnit/htmlunit-neko/security/advisories/GHSA-6jmm-mp6w-4rrg", + "https://nvd.nist.gov/vuln/detail/CVE-2022-29546" + ], + "PublishedDate": "2022-04-25T03:15:07.84Z", + "LastModifiedDate": "2026-06-17T04:40:24.073Z" + }, + { + "VulnerabilityID": "CVE-2026-34197", + "VendorIDs": [ + "GHSA-rxpj-7qvf-xv32" + ], + "PkgName": "org.apache.activemq:activemq-broker", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-broker-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-broker@5.15.9", + "UID": "219b2a692cbbebac" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.19.5, 6.2.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-34197", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:b33fc720dd88b65933c8e80059d99a67665ebaecb80b36a2cbf6e4df72cc137e", + "Title": "org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: Apache ActiveMQ: RCE via crafted discovery URI in Jolokia JMX-HTTP bridge", + "Description": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.\n\nApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including\nBrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).\n\nAn authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.\nBecause Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().\n\n\n\nThis issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3.\n\n\n\nUsers are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20", + "CWE-94", + "CWE-78" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/06/3", + "https://access.redhat.com/security/cve/CVE-2026-34197", + "https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt", + "https://bugzilla.redhat.com/show_bug.cgi?id=2455869", + "https://github.com/apache/activemq", + "https://nvd.nist.gov/vuln/detail/CVE-2026-34197", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34197.json", + "https://www.cisa.gov/known-exploited-vulnerabilities-catalog", + "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34197", + "https://www.cve.org/CVERecord?id=CVE-2026-34197" + ], + "PublishedDate": "2026-04-07T09:16:20.967Z", + "LastModifiedDate": "2026-08-04T13:18:20.95Z" + }, + { + "VulnerabilityID": "CVE-2026-39304", + "VendorIDs": [ + "GHSA-5568-6qcg-g7fx" + ], + "PkgName": "org.apache.activemq:activemq-broker", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-broker-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-broker@5.15.9", + "UID": "219b2a692cbbebac" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.19.4, 6.2.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39304", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:7b413459416d010ddc85c304608259e35b1ba4e5f9854f6ecf26cacde4e06b2d", + "Title": "Apache ActiveMQ Client: Apache ActiveMQ Broker: Apache ActiveMQ: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion", + "Description": "Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.\n\nActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.\n\nNote: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM. Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well.\nThis issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.4.\n\nUsers are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/09/17", + "https://access.redhat.com/security/cve/CVE-2026-39304", + "https://activemq.apache.org/security-advisories.data/CVE-2026-39304-announcement.txt", + "https://bugzilla.redhat.com/show_bug.cgi?id=2457275", + "https://github.com/apache/activemq", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39304", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39304.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39304" + ], + "PublishedDate": "2026-04-10T11:16:23.143Z", + "LastModifiedDate": "2026-07-15T02:20:45.36Z" + }, + { + "VulnerabilityID": "CVE-2026-40466", + "VendorIDs": [ + "GHSA-w3w2-mpp5-92gm" + ], + "PkgName": "org.apache.activemq:activemq-broker", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-broker-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-broker@5.15.9", + "UID": "219b2a692cbbebac" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.19.6, 6.2.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40466", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:0676e32d92046b38768d0af60dc13bdf732d51105bdc89dc623ea7b1ef6d27f7", + "Title": "org.apache.activemq/activemq-all: org.apache.activemq/activemq-broker: Apache ActiveMQ: Arbitrary code execution via improper input validation in HTTP Discovery transport", + "Description": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\n\n\nAn authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia if the activemq-http module is on the classpath.\nA malicious HTTP endpoint can return a VM transport through the HTTP URI which will bypass the validation added in CVE-2026-34197. The attacker can then use the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.\nBecause Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().\n\n\nThis issue affects Apache ActiveMQ Broker: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ All: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5.\n\nUsers are recommended to upgrade to version 5.19.6 or 6.2.5, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20", + "CWE-94" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-40466", + "https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt", + "https://bugzilla.redhat.com/show_bug.cgi?id=2461410", + "https://github.com/apache/activemq", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40466", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40466.json", + "https://www.cve.org/CVERecord?id=CVE-2026-40466" + ], + "PublishedDate": "2026-04-24T11:16:22.54Z", + "LastModifiedDate": "2026-07-15T02:21:06.12Z" + }, + { + "VulnerabilityID": "CVE-2026-41044", + "VendorIDs": [ + "GHSA-mr6m-xj7v-3cv3" + ], + "PkgName": "org.apache.activemq:activemq-broker", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-broker-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-broker@5.15.9", + "UID": "219b2a692cbbebac" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.19.6, 6.2.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-41044", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:0a962837fad8a055aef0a4d73535e9b3428ac6d0ec39c1cd2edfb13f0037dbc4", + "Title": "org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: Apache ActiveMQ: Arbitrary code execution via improper input validation in admin console", + "Description": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All.\n\nAn authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding that can be later used by a VM transport to load a remote Spring XML application.\nThe attacker can then use the DestinationView mbean to send a message to trigger a VM transport creation that will reference this malicious broker name which can lead to loading the malicious Spring XML context file.\n\n\nBecause Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().\n\nThis issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Broker: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ All: before 5.19.6, from 6.0.0 before 6.2.5.\n\nUsers are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20", + "CWE-94" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.2 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/23/6", + "https://access.redhat.com/security/cve/CVE-2026-41044", + "https://activemq.apache.org/security-advisories.data/CVE-2026-41044-announcement.txt", + "https://bugzilla.redhat.com/show_bug.cgi?id=2461409", + "https://github.com/apache/activemq", + "https://nvd.nist.gov/vuln/detail/CVE-2026-41044", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41044.json", + "https://www.cve.org/CVERecord?id=CVE-2026-41044" + ], + "PublishedDate": "2026-04-24T11:16:22.79Z", + "LastModifiedDate": "2026-07-15T02:21:12.62Z" + }, + { + "VulnerabilityID": "CVE-2026-42588", + "VendorIDs": [ + "GHSA-hg6c-8mvr-jqc9" + ], + "PkgName": "org.apache.activemq:activemq-broker", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-broker-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-broker@5.15.9", + "UID": "219b2a692cbbebac" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.19.7, 6.2.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42588", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:0622721ee988a7af2f912cb90fcc420428966937a2484f33ac562ef76a5bc6d4", + "Title": "Improper Input Validation, Improper Control of Generation of Code ('Co ...", + "Description": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\nApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including\nBrokerService.addNetworkConnector(String).\n\nAn authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter using the \"masterslave:// \" URL which can allow loading a Spring XML application context using ResourceXmlApplicationContext.\nBecause Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20", + "CWE-94" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/05/31/18", + "https://github.com/apache/activemq", + "https://lists.apache.org/thread/ns0zktfo16s9ql2mmtqtlb6p6xcs45xm", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42588" + ], + "PublishedDate": "2026-06-01T09:16:19.137Z", + "LastModifiedDate": "2026-07-22T07:10:00.107Z" + }, + { + "VulnerabilityID": "CVE-2026-45505", + "VendorIDs": [ + "GHSA-v853-w46p-fv2h" + ], + "PkgName": "org.apache.activemq:activemq-broker", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-broker-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-broker@5.15.9", + "UID": "219b2a692cbbebac" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.19.7, 6.2.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-45505", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:42de9004955f6d10e4e09e75a763bd1e131012b92eb44c093e578541ce505cc1", + "Title": "activemq: Apache ActiveMQ: Arbitrary Code Execution via crafted discovery URI bypass", + "Description": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\n\nNon-parenthesized discovery wrappers such as `masterslave:vm://...,...`\nand `static:vm://...` incorrectly pass validation allowing bypass of fix in CVE-2026-34197. \n\nOriginal description from CVE-2026-34197.\n\nApache ActiveMQ exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery UR that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). \nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20", + "CWE-94" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-45505", + "https://github.com/apache/activemq", + "https://lists.apache.org/thread/7n97nddyw96w6ykldjv1h40jx86xdo0w", + "https://nvd.nist.gov/vuln/detail/CVE-2026-34197", + "https://nvd.nist.gov/vuln/detail/CVE-2026-45505", + "https://www.cve.org/CVERecord?id=CVE-2026-45505" + ], + "PublishedDate": "2026-06-01T09:16:19.7Z", + "LastModifiedDate": "2026-07-21T19:10:00.107Z" + }, + { + "VulnerabilityID": "CVE-2023-46604", + "VendorIDs": [ + "GHSA-crg9-44h2-xw35" + ], + "PkgName": "org.apache.activemq:activemq-client", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-client-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-client@5.15.9", + "UID": "36d1b8e723cfe1ab" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.15.16, 5.16.7, 5.17.6, 5.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-46604", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:8ddbaeb056a0311e325ef205774960502de0bc953ae318cd5194e71736249526", + "Title": "activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack", + "Description": "The Java OpenWire protocol marshaller is vulnerable to Remote Code \nExecution. This vulnerability may allow a remote attacker with network \naccess to either a Java-based OpenWire broker or client to run arbitrary\n shell commands by manipulating serialized class types in the OpenWire \nprotocol to cause either the client or the broker (respectively) to \ninstantiate any class on the classpath.\n\nUsers are recommended to upgrade\n both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 \nwhich fixes this issue.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "bitnami": 4, + "ghsa": 4, + "nvd": 4, + "redhat": 4, + "ubuntu": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H/E:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "http://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html", + "http://seclists.org/fulldisclosure/2024/Apr/18", + "http://www.openwall.com/lists/oss-security/2023/10/27/5", + "https://access.redhat.com/security/cve/CVE-2023-46604", + "https://activemq.apache.org/security-advisories.data/CVE-2023-46604", + "https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt", + "https://github.com/apache/activemq", + "https://github.com/apache/activemq/commit/22442b2385b1000312aec3d19e510131d595a5fc", + "https://github.com/apache/activemq/commit/80089f9f476afab7d976f5fc37c5ab4aa0c2139d", + "https://github.com/apache/activemq/commit/958330df26cf3d5cdb63905dc2c6882e98781d8f", + "https://github.com/apache/activemq/commit/9905e2a5bf9862a049f94ce0a2465b0c7ad52436", + "https://github.com/apache/activemq/commit/d0ccdd31544ada83185554c87c7aa141064020f0", + "https://github.com/apache/activemq/pull/1098", + "https://issues.apache.org/jira/browse/AMQ-9370", + "https://lists.apache.org/thread/y1ztwb3gktny47mj9sdv2sbw49nkgsgp", + "https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html", + "https://lists.debian.org/debian-lts-announce/2024/10/msg00027.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-46604", + "https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html", + "https://security.netapp.com/advisory/ntap-20231110-0010", + "https://security.netapp.com/advisory/ntap-20231110-0010/", + "https://ubuntu.com/security/notices/USN-6910-1", + "https://ubuntu.com/security/notices/USN-7268-1", + "https://www.cisa.gov/known-exploited-vulnerabilities-catalog", + "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46604", + "https://www.cve.org/CVERecord?id=CVE-2023-46604", + "https://www.openwall.com/lists/oss-security/2023/10/27/5" + ], + "PublishedDate": "2023-10-27T15:15:14.017Z", + "LastModifiedDate": "2026-06-17T06:31:11.37Z" + }, + { + "VulnerabilityID": "CVE-2026-39304", + "VendorIDs": [ + "GHSA-5568-6qcg-g7fx" + ], + "PkgName": "org.apache.activemq:activemq-client", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-client-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-client@5.15.9", + "UID": "36d1b8e723cfe1ab" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.19.4, 6.2.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39304", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:7b413459416d010ddc85c304608259e35b1ba4e5f9854f6ecf26cacde4e06b2d", + "Title": "Apache ActiveMQ Client: Apache ActiveMQ Broker: Apache ActiveMQ: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion", + "Description": "Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.\n\nActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.\n\nNote: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM. Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well.\nThis issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.4.\n\nUsers are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/09/17", + "https://access.redhat.com/security/cve/CVE-2026-39304", + "https://activemq.apache.org/security-advisories.data/CVE-2026-39304-announcement.txt", + "https://bugzilla.redhat.com/show_bug.cgi?id=2457275", + "https://github.com/apache/activemq", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39304", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39304.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39304" + ], + "PublishedDate": "2026-04-10T11:16:23.143Z", + "LastModifiedDate": "2026-07-15T02:20:45.36Z" + }, + { + "VulnerabilityID": "CVE-2023-46604", + "VendorIDs": [ + "GHSA-crg9-44h2-xw35" + ], + "PkgName": "org.apache.activemq:activemq-openwire-legacy", + "PkgPath": "usr/local/share/InterProScan/lib/activemq-openwire-legacy-5.15.9.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@5.15.9", + "UID": "90cf7fb5a0b57a61" + }, + "InstalledVersion": "5.15.9", + "FixedVersion": "5.15.16, 5.16.7, 5.17.6, 5.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-46604", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:8ddbaeb056a0311e325ef205774960502de0bc953ae318cd5194e71736249526", + "Title": "activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack", + "Description": "The Java OpenWire protocol marshaller is vulnerable to Remote Code \nExecution. This vulnerability may allow a remote attacker with network \naccess to either a Java-based OpenWire broker or client to run arbitrary\n shell commands by manipulating serialized class types in the OpenWire \nprotocol to cause either the client or the broker (respectively) to \ninstantiate any class on the classpath.\n\nUsers are recommended to upgrade\n both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 \nwhich fixes this issue.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "bitnami": 4, + "ghsa": 4, + "nvd": 4, + "redhat": 4, + "ubuntu": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H/E:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "http://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html", + "http://seclists.org/fulldisclosure/2024/Apr/18", + "http://www.openwall.com/lists/oss-security/2023/10/27/5", + "https://access.redhat.com/security/cve/CVE-2023-46604", + "https://activemq.apache.org/security-advisories.data/CVE-2023-46604", + "https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt", + "https://github.com/apache/activemq", + "https://github.com/apache/activemq/commit/22442b2385b1000312aec3d19e510131d595a5fc", + "https://github.com/apache/activemq/commit/80089f9f476afab7d976f5fc37c5ab4aa0c2139d", + "https://github.com/apache/activemq/commit/958330df26cf3d5cdb63905dc2c6882e98781d8f", + "https://github.com/apache/activemq/commit/9905e2a5bf9862a049f94ce0a2465b0c7ad52436", + "https://github.com/apache/activemq/commit/d0ccdd31544ada83185554c87c7aa141064020f0", + "https://github.com/apache/activemq/pull/1098", + "https://issues.apache.org/jira/browse/AMQ-9370", + "https://lists.apache.org/thread/y1ztwb3gktny47mj9sdv2sbw49nkgsgp", + "https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html", + "https://lists.debian.org/debian-lts-announce/2024/10/msg00027.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-46604", + "https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html", + "https://security.netapp.com/advisory/ntap-20231110-0010", + "https://security.netapp.com/advisory/ntap-20231110-0010/", + "https://ubuntu.com/security/notices/USN-6910-1", + "https://ubuntu.com/security/notices/USN-7268-1", + "https://www.cisa.gov/known-exploited-vulnerabilities-catalog", + "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46604", + "https://www.cve.org/CVERecord?id=CVE-2023-46604", + "https://www.openwall.com/lists/oss-security/2023/10/27/5" + ], + "PublishedDate": "2023-10-27T15:15:14.017Z", + "LastModifiedDate": "2026-06-17T06:31:11.37Z" + }, + { + "VulnerabilityID": "CVE-2022-42889", + "VendorIDs": [ + "GHSA-599f-7c49-w659" + ], + "PkgName": "org.apache.commons:commons-text", + "PkgPath": "usr/local/share/InterProScan/lib/commons-text-1.8.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.apache.commons/commons-text@1.8", + "UID": "dee18e508d6064ee" + }, + "InstalledVersion": "1.8", + "FixedVersion": "1.10.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-42889", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:a42e6daeabf973848028d6c787ac5d9b0b0ba398d4a7872da217e1a3b15690e4", + "Title": "apache-commons-text: variable interpolation RCE", + "Description": "Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is \"${prefix:name}\", where \"prefix\" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - \"script\" - execute expressions using the JVM script execution engine (javax.script) - \"dns\" - resolve dns records - \"url\" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 4, + "redhat": 4, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "http://packetstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Server-Side-Request-Forgery.html", + "http://packetstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-Execution.html", + "http://seclists.org/fulldisclosure/2023/Feb/3", + "http://www.openwall.com/lists/oss-security/2022/10/13/4", + "http://www.openwall.com/lists/oss-security/2022/10/18/1", + "https://access.redhat.com/security/cve/CVE-2022-42889", + "https://arxiv.org/pdf/2306.05534", + "https://blogs.apache.org/security/entry/cve-2022-42889", + "https://github.com/apache/commons-text", + "https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om", + "https://nvd.nist.gov/vuln/detail/CVE-2022-42889", + "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0022", + "https://seclists.org/oss-sec/2022/q4/22", + "https://security.gentoo.org/glsa/202301-05", + "https://security.netapp.com/advisory/ntap-20221020-0004", + "https://security.netapp.com/advisory/ntap-20221020-0004/", + "https://securitylab.github.com/advisories/GHSL-2022-018_Apache_Commons_Text", + "https://www.cve.org/CVERecord?id=CVE-2022-42889" + ], + "PublishedDate": "2022-10-13T13:15:10.113Z", + "LastModifiedDate": "2026-06-17T05:05:31.85Z" + }, + { + "VulnerabilityID": "CVE-2020-10683", + "VendorIDs": [ + "GHSA-hwj3-m3p6-hj38" + ], + "PkgName": "org.dom4j:dom4j", + "PkgPath": "usr/local/share/InterProScan/lib/dom4j-2.1.1.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.dom4j/dom4j@2.1.1", + "UID": "20b2dcbc5c200054" + }, + "InstalledVersion": "2.1.1", + "FixedVersion": "2.0.3, 2.1.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-10683", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:936114a445d712dea9f41f51c919656063f31403858c782f585ccc133984a59f", + "Title": "dom4j: XML External Entity vulnerability in default SAX parser", + "Description": "dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-611" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 4, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 7.4 + } + }, + "References": [ + "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00061.html", + "https://access.redhat.com/security/cve/CVE-2020-10683", + "https://bugzilla.redhat.com/show_bug.cgi?id=1694235", + "https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html", + "https://github.com/dom4j/dom4j", + "https://github.com/dom4j/dom4j/commit/1707bf3d898a8ada3b213acb0e3b38f16eaae73d", + "https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658", + "https://github.com/dom4j/dom4j/commits/version-2.0.3", + "https://github.com/dom4j/dom4j/issues/87", + "https://github.com/dom4j/dom4j/releases/tag/version-2.1.3", + "https://lists.apache.org/thread.html/r51f3f9801058e47153c0ad9bc6209d57a592fc0e7aefd787760911b8@%3Cdev.velocity.apache.org%3E", + "https://lists.apache.org/thread.html/r91c64cd51e68e97d524395474eaa25362d564572276b9917fcbf5c32@%3Cdev.velocity.apache.org%3E", + "https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51@%3Cnotifications.freemarker.apache.org%3E", + "https://nvd.nist.gov/vuln/detail/CVE-2020-10683", + "https://security.netapp.com/advisory/ntap-20200518-0002", + "https://security.netapp.com/advisory/ntap-20200518-0002/", + "https://ubuntu.com/security/notices/USN-4575-1", + "https://usn.ubuntu.com/4575-1", + "https://usn.ubuntu.com/4575-1/", + "https://www.cve.org/CVERecord?id=CVE-2020-10683", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuApr2021.html", + "https://www.oracle.com/security-alerts/cpujan2021.html", + "https://www.oracle.com/security-alerts/cpujan2022.html", + "https://www.oracle.com/security-alerts/cpujul2020.html", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://www.oracle.com/security-alerts/cpuoct2020.html", + "https://www.oracle.com/security-alerts/cpuoct2021.html" + ], + "PublishedDate": "2020-05-01T19:15:12.927Z", + "LastModifiedDate": "2026-06-17T02:48:14.817Z" + }, + { + "VulnerabilityID": "CVE-2026-2332", + "VendorIDs": [ + "GHSA-355h-qmc2-wpwf" + ], + "PkgName": "org.eclipse.jetty:jetty-http", + "PkgPath": "usr/local/share/InterProScan/lib/jetty-http-11.0.10.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.eclipse.jetty/jetty-http@11.0.10", + "UID": "6db267f4c80ecc4c" + }, + "InstalledVersion": "11.0.10", + "FixedVersion": "12.1.7, 12.0.33, 11.0.29, 10.0.28, 9.4.60", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-2332", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:52ab965a268f227dece134126f6040ee674e601db8a4d5a528cb5cc03865663f", + "Title": "org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing", + "Description": "In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n * https://w4ke.info/2025/06/18/funky-chunks.html\n\n * https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-444" + ], + "VendorSeverity": { + "alma": 3, + "ghsa": 3, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:14272", + "https://access.redhat.com/errata/RHSA-2026:17668", + "https://access.redhat.com/errata/RHSA-2026:20568", + "https://access.redhat.com/errata/RHSA-2026:21773", + "https://access.redhat.com/errata/RHSA-2026:22453", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:50221", + "https://access.redhat.com/errata/RHSA-2026:50222", + "https://access.redhat.com/errata/RHSA-2026:50223", + "https://access.redhat.com/errata/RHSA-2026:50263", + "https://access.redhat.com/security/cve/CVE-2026-2332", + "https://bugzilla.redhat.com/2419500", + "https://bugzilla.redhat.com/2458187", + "https://bugzilla.redhat.com/show_bug.cgi?id=2458187", + "https://errata.almalinux.org/9/ALSA-2026-20568.html", + "https://github.com/jetty/jetty.project", + "https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf", + "https://gitlab.eclipse.org/security/cve-assignment/-/issues/89", + "https://linux.oracle.com/cve/CVE-2026-2332.html", + "https://linux.oracle.com/errata/ELSA-2026-20568.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-2332", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json", + "https://w4ke.info/2025/06/18/funky-chunks.html", + "https://www.cve.org/CVERecord?id=CVE-2026-2332" + ], + "PublishedDate": "2026-04-14T12:16:21.333Z", + "LastModifiedDate": "2026-08-14T13:17:52.237Z" + }, + { + "VulnerabilityID": "CVE-2024-7708", + "VendorIDs": [ + "GHSA-9299-c6m4-mjhc" + ], + "PkgName": "org.eclipse.jetty:jetty-server", + "PkgPath": "usr/local/share/InterProScan/lib/jetty-server-11.0.10.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.eclipse.jetty/jetty-server@11.0.10", + "UID": "8fcf3a0d90b59075" + }, + "InstalledVersion": "11.0.10", + "FixedVersion": "10.0.23, 11.0.23", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-7708", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:4ccebbd3053834b1a33ec2950195a773f383e9580712fb339f72b48cb03771bb", + "Title": "Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests", + "Description": "For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.\nThis is particularly the case for 100-Continue, but any request where the network is slow can leak.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-401" + ], + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/jetty/jetty.project", + "https://github.com/jetty/jetty.project/commit/8259eabbc70ae7fc2d525f1e95b43fbdfd2ad097", + "https://github.com/jetty/jetty.project/pull/12156", + "https://github.com/jetty/jetty.project/releases/tag/jetty-10.0.23", + "https://github.com/jetty/jetty.project/releases/tag/jetty-11.0.23", + "https://github.com/jetty/jetty.project/security/advisories/GHSA-9299-c6m4-mjhc", + "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/29", + "https://nvd.nist.gov/vuln/detail/CVE-2024-7708" + ], + "PublishedDate": "2026-07-14T09:16:39.453Z", + "LastModifiedDate": "2026-07-14T20:56:01.53Z" + }, + { + "VulnerabilityID": "CVE-2020-25638", + "VendorIDs": [ + "GHSA-j8jw-g6fq-mp7h" + ], + "PkgName": "org.hibernate:hibernate-core", + "PkgPath": "usr/local/share/InterProScan/lib/hibernate-core-5.4.2.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.hibernate/hibernate-core@5.4.2.Final", + "UID": "58247fed706a9c63" + }, + "InstalledVersion": "5.4.2.Final", + "FixedVersion": "5.4.24.Final, 5.3.20.Final", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2020-25638", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:430b7acebb5358fecac03fefedca6ea119450e46ede903ce834f9f95bedbd312", + "Title": "hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used", + "Description": "A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-89" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V2Score": 5.8, + "V3Score": 7.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2020-25638", + "https://bugzilla.redhat.com/show_bug.cgi?id=1881353", + "https://github.com/hibernate/hibernate-orm", + "https://github.com/hibernate/hibernate-orm/commit/36ebf7d3836e83e99f2a91777b5389e1daf1f2b7", + "https://github.com/hibernate/hibernate-orm/commit/59fede7acaaa1579b561407aefa582311f7ebe78", + "https://github.com/hibernate/hibernate-orm/commit/d22bbb5c339c9df7712c3365bb1df97c91b35ec5", + "https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44@%3Cdev.turbine.apache.org%3E", + "https://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df@%3Ccommits.turbine.apache.org%3E", + "https://lists.debian.org/debian-lts-announce/2021/01/msg00000.html", + "https://nvd.nist.gov/vuln/detail/CVE-2020-25638", + "https://ubuntu.com/security/notices/USN-6845-1", + "https://www.cve.org/CVERecord?id=CVE-2020-25638", + "https://www.debian.org/security/2021/dsa-4908", + "https://www.oracle.com//security-alerts/cpujul2021.html", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2020-12-02T15:15:12.377Z", + "LastModifiedDate": "2026-06-17T03:07:01.623Z" + }, + { + "VulnerabilityID": "CVE-2026-0603", + "VendorIDs": [ + "GHSA-2p5w-cvg5-gc5c" + ], + "PkgName": "org.hibernate:hibernate-core", + "PkgPath": "usr/local/share/InterProScan/lib/hibernate-core-5.4.2.Final.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.hibernate/hibernate-core@5.4.2.Final", + "UID": "58247fed706a9c63" + }, + "InstalledVersion": "5.4.2.Final", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-0603", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:1a5e75ecaa9422ef7bb7680a6c13c4da4fc19adc1255874fac38667cf203ae7a", + "Title": "org.hibernate/hibernate-core: Hibernate: Information disclosure and data deletion via second-order SQL injection", + "Description": "A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-89" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L", + "V3Score": 8.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L", + "V3Score": 8.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4915", + "https://access.redhat.com/errata/RHSA-2026:4916", + "https://access.redhat.com/errata/RHSA-2026:4917", + "https://access.redhat.com/errata/RHSA-2026:4924", + "https://access.redhat.com/errata/RHSA-2026:6011", + "https://access.redhat.com/errata/RHSA-2026:6012", + "https://access.redhat.com/security/cve/CVE-2026-0603", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427147", + "https://github.com/hibernate/hibernate-orm", + "https://nvd.nist.gov/vuln/detail/CVE-2026-0603", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0603.json", + "https://www.cve.org/CVERecord?id=CVE-2026-0603" + ], + "PublishedDate": "2026-01-23T07:15:53.66Z", + "LastModifiedDate": "2026-07-28T13:17:29.203Z" + }, + { + "VulnerabilityID": "CVE-2023-20863", + "VendorIDs": [ + "GHSA-wxqc-pxw9-g2p8" + ], + "PkgName": "org.springframework:spring-expression", + "PkgPath": "usr/local/share/InterProScan/lib/spring-expression-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-expression@5.2.22.RELEASE", + "UID": "be4ba0927ae956de" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "6.0.8, 5.3.27, 5.2.24.RELEASE", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-20863", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:7a957ec1d25bd40b62e0bc480d49b4c1e2c5ba6ff1a34d301828c80d5659fbeb", + "Title": "springframework: Spring Expression DoS Vulnerability", + "Description": "In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-917" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 2, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2023-20863", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/commit/965a6392757d20f9db19241126fcc719a51eac15", + "https://github.com/spring-projects/spring-framework/commit/b73f5fcac22555f844cf27a7eeb876cb9d7f7f7e", + "https://github.com/spring-projects/spring-framework/commit/ebc82654282bda547fbc20a9749ab1bda886a46f", + "https://nvd.nist.gov/vuln/detail/CVE-2023-20863", + "https://security.netapp.com/advisory/ntap-20240524-0015", + "https://security.netapp.com/advisory/ntap-20240524-0015/", + "https://spring.io/security/cve-2023-20863", + "https://www.cve.org/CVERecord?id=CVE-2023-20863" + ], + "PublishedDate": "2023-04-13T20:15:07.777Z", + "LastModifiedDate": "2026-06-17T05:31:02.697Z" + }, + { + "VulnerabilityID": "CVE-2026-41849", + "VendorIDs": [ + "GHSA-775g-4xr8-78h8" + ], + "PkgName": "org.springframework:spring-expression", + "PkgPath": "usr/local/share/InterProScan/lib/spring-expression-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-expression@5.2.22.RELEASE", + "UID": "be4ba0927ae956de" + }, + "InstalledVersion": "5.2.22.RELEASE", + "Status": "affected", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-41849", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:4ffd44790e1c0f5c286390b3aa790e7ddfa5286015698ea423f7317d19ac880b", + "Title": "spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL", + "Description": "An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).\n\nAffected versions:\nSpring Framework 5.3.0 through 5.3.48.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-41849", + "https://github.com/spring-projects/spring-framework", + "https://nvd.nist.gov/vuln/detail/CVE-2026-41849", + "https://spring.io/security/cve-2026-41849", + "https://www.cve.org/CVERecord?id=CVE-2026-41849" + ], + "PublishedDate": "2026-06-09T05:16:37.06Z", + "LastModifiedDate": "2026-07-23T08:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-41850", + "VendorIDs": [ + "GHSA-r5w3-xv2f-j59q" + ], + "PkgName": "org.springframework:spring-expression", + "PkgPath": "usr/local/share/InterProScan/lib/spring-expression-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-expression@5.2.22.RELEASE", + "UID": "be4ba0927ae956de" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "7.0.8, 6.2.19", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-41850", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:ceac0f907e2a77ececd4b78692826e7f2108c9f837c02b8d6725cf0aeef1733b", + "Title": "spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions", + "Description": "Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.\n\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-41850", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19", + "https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8", + "https://nvd.nist.gov/vuln/detail/CVE-2026-41850", + "https://spring.io/security/cve-2026-41850", + "https://www.cve.org/CVERecord?id=CVE-2026-41850" + ], + "PublishedDate": "2026-06-09T05:16:37.177Z", + "LastModifiedDate": "2026-07-23T08:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2016-1000027", + "VendorIDs": [ + "GHSA-4wrc-f8pq-fpqp" + ], + "PkgName": "org.springframework:spring-web", + "PkgPath": "usr/local/share/InterProScan/lib/spring-web-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-web@5.2.22.RELEASE", + "UID": "fca650a47ce24baf" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "6.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2016-1000027", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:2327420129766d9b10cf2d3357d689a92c8f474c657ecaac03484875c1a24968", + "Title": "spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization", + "Description": "Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 4, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V2Vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 6.8, + "V3Score": 9.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2016-1000027", + "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/commit/2b051b8b321768a4cfef83077db65c6328ffd60f", + "https://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa", + "https://github.com/spring-projects/spring-framework/issues/21680", + "https://github.com/spring-projects/spring-framework/issues/24434", + "https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-1231625331", + "https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626", + "https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417", + "https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525", + "https://jira.spring.io/browse/SPR-17143?redirect=false", + "https://nvd.nist.gov/vuln/detail/CVE-2016-1000027", + "https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.json", + "https://security-tracker.debian.org/tracker/CVE-2016-1000027", + "https://security.netapp.com/advisory/ntap-20230420-0009", + "https://security.netapp.com/advisory/ntap-20230420-0009/", + "https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now", + "https://support.contrastsecurity.com/hc/en-us/articles/4402400830612-Spring-web-Java-Deserialization-CVE-2016-1000027", + "https://www.cve.org/CVERecord?id=CVE-2016-1000027", + "https://www.tenable.com/security/research/tra-2016-20" + ], + "PublishedDate": "2020-01-02T23:15:11.857Z", + "LastModifiedDate": "2024-11-21T02:42:50.717Z" + }, + { + "VulnerabilityID": "CVE-2024-22243", + "VendorIDs": [ + "GHSA-ccgv-vj62-xf9h" + ], + "PkgName": "org.springframework:spring-web", + "PkgPath": "usr/local/share/InterProScan/lib/spring-web-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-web@5.2.22.RELEASE", + "UID": "fca650a47ce24baf" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "6.1.4, 6.0.17, 5.3.32", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-22243", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:69d567f21e1ea8bfae7530b30645714c9bf53b690e48ae7238846157af6384bb", + "Title": "springframework: URL Parsing with Host Validation", + "Description": "Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-601" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N", + "V3Score": 3.4 + } + }, + "References": [ + "http://seclists.org/fulldisclosure/2024/Sep/24", + "https://access.redhat.com/security/cve/CVE-2024-22243", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/blob/main/spring-web/src/main/java/org/springframework/web/util/UriComponentsBuilder.java", + "https://nvd.nist.gov/vuln/detail/CVE-2024-22243", + "https://security.netapp.com/advisory/ntap-20240524-0001", + "https://security.netapp.com/advisory/ntap-20240524-0001/", + "https://spring.io/security/cve-2024-22243", + "https://www.cve.org/CVERecord?id=CVE-2024-22243" + ], + "PublishedDate": "2024-02-23T05:15:08.143Z", + "LastModifiedDate": "2026-06-17T07:11:01.04Z" + }, + { + "VulnerabilityID": "CVE-2024-22259", + "VendorIDs": [ + "GHSA-hgjh-9rj2-g67j" + ], + "PkgName": "org.springframework:spring-web", + "PkgPath": "usr/local/share/InterProScan/lib/spring-web-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-web@5.2.22.RELEASE", + "UID": "fca650a47ce24baf" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "6.1.5, 6.0.18, 5.3.33", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-22259", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:2c93ae1f59fa6c4b24f23097b20e764f71d02e9d93c89cb25e39b12fe79c0dce", + "Title": "springframework: URL Parsing with Host Validation", + "Description": "Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-601" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2024-22259", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/commit/297cbae2990e1413537c55845a7e0ea0ffd9f9bb", + "https://github.com/spring-projects/spring-framework/commit/381f790329a48b74c2a49fc1384dd68ca9153501", + "https://github.com/spring-projects/spring-framework/commit/f2fd2f12269c6a781c5b2c20b3c24141055a3d68", + "https://nvd.nist.gov/vuln/detail/CVE-2024-22259", + "https://security.netapp.com/advisory/ntap-20240524-0002", + "https://security.netapp.com/advisory/ntap-20240524-0002/", + "https://spring.io/security/cve-2024-22259", + "https://www.cve.org/CVERecord?id=CVE-2024-22259" + ], + "PublishedDate": "2024-03-16T05:15:20.83Z", + "LastModifiedDate": "2026-06-17T07:11:03.053Z" + }, + { + "VulnerabilityID": "CVE-2024-22262", + "VendorIDs": [ + "GHSA-2wrp-6fg6-hmc5" + ], + "PkgName": "org.springframework:spring-web", + "PkgPath": "usr/local/share/InterProScan/lib/spring-web-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-web@5.2.22.RELEASE", + "UID": "fca650a47ce24baf" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "5.3.34, 6.0.19, 6.1.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-22262", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:daf0ba1de575e65014f5c3465a6d51551a92dbef5b0820f2c3b661ea62741740", + "Title": "springframework: URL Parsing with Host Validation", + "Description": "Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259  and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-601", + "CWE-918" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2024-22262", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/blob/main/spring-web/src/main/java/org/springframework/web/util/UriComponentsBuilder.java", + "https://nvd.nist.gov/vuln/detail/CVE-2024-22262", + "https://security.netapp.com/advisory/ntap-20240524-0003", + "https://security.netapp.com/advisory/ntap-20240524-0003/", + "https://spring.io/security/cve-2024-22262", + "https://www.cve.org/CVERecord?id=CVE-2024-22262" + ], + "PublishedDate": "2024-04-16T06:15:46.27Z", + "LastModifiedDate": "2026-06-17T07:11:03.473Z" + }, + { + "VulnerabilityID": "CVE-2024-38819", + "VendorIDs": [ + "GHSA-g5vr-rgqm-vf78" + ], + "PkgName": "org.springframework:spring-webmvc", + "PkgPath": "usr/local/share/InterProScan/lib/spring-webmvc-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-webmvc@5.2.22.RELEASE", + "UID": "fc33d440913be8f" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "6.1.14", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-38819", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:c4d71311f9e955da8561c1c114776d0e1b41c85ce63275e26bc2e7587e83feec", + "Title": "org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks", + "Description": "Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2024-38819", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/commit/3bfbe30a7814c9ea1556d40df9bd87ddb3ba372d", + "https://github.com/spring-projects/spring-framework/commit/fb7890d73975a3d9e0763e0926df2bd0a608e87e", + "https://github.com/spring-projects/spring-framework/issues/33689", + "https://nvd.nist.gov/vuln/detail/CVE-2024-38819", + "https://security.netapp.com/advisory/ntap-20250110-0010", + "https://security.netapp.com/advisory/ntap-20250110-0010/", + "https://spring.io/security/cve-2024-38819", + "https://www.cve.org/CVERecord?id=CVE-2024-38819" + ], + "PublishedDate": "2024-12-19T18:15:10.557Z", + "LastModifiedDate": "2026-06-17T07:41:06.397Z" + }, + { + "VulnerabilityID": "CVE-2026-41842", + "VendorIDs": [ + "GHSA-x23c-287f-qqv5" + ], + "PkgName": "org.springframework:spring-webmvc", + "PkgPath": "usr/local/share/InterProScan/lib/spring-webmvc-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-webmvc@5.2.22.RELEASE", + "UID": "fc33d440913be8f" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "7.0.8, 6.2.19", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-41842", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:e08a1e5a68eb1f3f68182879d525b7cc928aa15649f5506bccbc7ffa0b9c5b5a", + "Title": "spring-framework: Spring Framework: Denial of Service when resolving static resources", + "Description": "Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.\n\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-41842", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19", + "https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8", + "https://nvd.nist.gov/vuln/detail/CVE-2026-41842", + "https://spring.io/security/cve-2026-41842", + "https://www.cve.org/CVERecord?id=CVE-2026-41842" + ], + "PublishedDate": "2026-06-09T05:16:36.203Z", + "LastModifiedDate": "2026-07-23T08:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-41845", + "VendorIDs": [ + "GHSA-3chg-m5w7-qfv5" + ], + "PkgName": "org.springframework:spring-webmvc", + "PkgPath": "usr/local/share/InterProScan/lib/spring-webmvc-5.2.22.RELEASE.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/org.springframework/spring-webmvc@5.2.22.RELEASE", + "UID": "fc33d440913be8f" + }, + "InstalledVersion": "5.2.22.RELEASE", + "FixedVersion": "7.0.8, 6.2.19", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-41845", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:57c294daa38cc4c22f4c51d0689303eb400209014bf73babd756278610b83f49", + "Title": "org.springframework: Spring Framework: Cross-site scripting (XSS) via incorrect JavaScript escaping", + "Description": "Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability.\n\nAffected versions:\nSpring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 2, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N", + "V3Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 6.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-41845", + "https://github.com/spring-projects/spring-framework", + "https://github.com/spring-projects/spring-framework/commit/86d99790dbaa8ce6bb1087ef92844d0abfdab015", + "https://github.com/spring-projects/spring-framework/commit/a1826b725c29fbb175fa7b4fc005aa3d78c32015", + "https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19", + "https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8", + "https://nvd.nist.gov/vuln/detail/CVE-2026-41845", + "https://spring.io/security/cve-2026-41845", + "https://www.cve.org/CVERecord?id=CVE-2026-41845" + ], + "PublishedDate": "2026-06-09T05:16:36.557Z", + "LastModifiedDate": "2026-07-23T08:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2022-34169", + "VendorIDs": [ + "GHSA-9339-86wc-4qgf" + ], + "PkgName": "xalan:xalan", + "PkgPath": "usr/local/share/InterProScan/lib/xalan-2.7.2.jar", + "PkgIdentifier": { + "PURL": "pkg:maven/xalan/xalan@2.7.2", + "UID": "5f39e849e936b97d" + }, + "InstalledVersion": "2.7.2", + "FixedVersion": "2.7.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-34169", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Maven", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven" + }, + "Fingerprint": "sha256:4cb7335bfe1d18a1830d24a815f0ab328cf49e543a5e978447a56b010cbf1088", + "Title": "OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407)", + "Description": "The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-681" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "bitnami": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.html", + "http://www.openwall.com/lists/oss-security/2022/07/19/5", + "http://www.openwall.com/lists/oss-security/2022/07/19/6", + "http://www.openwall.com/lists/oss-security/2022/07/20/2", + "http://www.openwall.com/lists/oss-security/2022/07/20/3", + "http://www.openwall.com/lists/oss-security/2022/10/18/2", + "http://www.openwall.com/lists/oss-security/2022/11/04/8", + "http://www.openwall.com/lists/oss-security/2022/11/07/2", + "https://access.redhat.com/errata/RHSA-2022:5736", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-21540.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-21541.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-21549.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-34169.json", + "https://access.redhat.com/security/cve/CVE-2022-34169", + "https://bugzilla.redhat.com/2108540", + "https://bugzilla.redhat.com/2108543", + "https://bugzilla.redhat.com/2108547", + "https://bugzilla.redhat.com/2108554", + "https://errata.almalinux.org/9/ALSA-2022-5736.html", + "https://gitbox.apache.org/repos/asf?p=xalan-java.git", + "https://gitbox.apache.org/repos/asf?p=xalan-java.git;a=commit;h=2e60d0a9a5b822c4abf9051857973b1c6babfe81", + "https://gitbox.apache.org/repos/asf?p=xalan-java.git;a=commit;h=ab57211e5d2e97cbed06786f919fa9b749c83573", + "https://gitbox.apache.org/repos/asf?p=xalan-java.git;a=commit;h=da3e0d06b467247643ce04e88d3346739d119f21", + "https://github.com/openjdk/jdk/commit/41ef2b249073450172e11163a4d05762364b1297", + "https://linux.oracle.com/cve/CVE-2022-34169.html", + "https://linux.oracle.com/errata/ELSA-2022-9656.html", + "https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw", + "https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8", + "https://lists.apache.org/thread/x3f7xv3p1g32qj2hlg8wd57pwcpld471", + "https://lists.debian.org/debian-lts-announce/2022/10/msg00024.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/", + "https://marc.info/?l=oss-security&m=165825217622132", + "https://nvd.nist.gov/vuln/detail/CVE-2022-34169", + "https://openjdk.org/groups/vulnerability/advisories/2022-07-19", + "https://security.gentoo.org/glsa/202401-25", + "https://security.netapp.com/advisory/ntap-20220729-0009", + "https://security.netapp.com/advisory/ntap-20220729-0009/", + "https://security.netapp.com/advisory/ntap-20240621-0006", + "https://security.netapp.com/advisory/ntap-20240621-0006/", + "https://ubuntu.com/security/notices/USN-5546-1", + "https://ubuntu.com/security/notices/USN-5546-2", + "https://www.cve.org/CVERecord?id=CVE-2022-34169", + "https://www.debian.org/security/2022/dsa-5188", + "https://www.debian.org/security/2022/dsa-5192", + "https://www.debian.org/security/2022/dsa-5256", + "https://www.oracle.com/security-alerts/cpujul2022.html", + "https://xalan.apache.org" + ], + "PublishedDate": "2022-07-19T18:15:11.74Z", + "LastModifiedDate": "2026-06-17T04:49:50.163Z" + }, + { + "VulnerabilityID": "CVE-2024-6345", + "VendorIDs": [ + "GHSA-cx63-2mw6-8hw5" + ], + "PkgName": "setuptools", + "PkgPath": "usr/local/lib/python3.11/site-packages/setuptools-65.5.1-py3.11.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@65.5.1", + "UID": "9bb97bbc4162777a" + }, + "InstalledVersion": "65.5.1", + "FixedVersion": "70.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-6345", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:33d3f0a97340c79d51ddcc7175cd3de7aa004f755f4d4522983a140e34166964", + "Title": "pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools", + "Description": "A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "ghsa": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 8.8, + "V40Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:6726", + "https://access.redhat.com/security/cve/CVE-2024-6345", + "https://bugzilla.redhat.com/2297771", + "https://bugzilla.redhat.com/show_bug.cgi?id=2297771", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6345", + "https://errata.almalinux.org/9/ALSA-2024-6726.html", + "https://errata.rockylinux.org/RLSA-2024:6726", + "https://github.com/advisories/GHSA-cx63-2mw6-8hw5", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0", + "https://github.com/pypa/setuptools/pull/4332", + "https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5", + "https://linux.oracle.com/cve/CVE-2024-6345.html", + "https://linux.oracle.com/errata/ELSA-2024-6726.html", + "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-6345", + "https://ubuntu.com/security/notices/USN-7002-1", + "https://www.cve.org/CVERecord?id=CVE-2024-6345" + ], + "PublishedDate": "2024-07-15T01:15:01.73Z", + "LastModifiedDate": "2026-06-17T08:17:49.463Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgName": "setuptools", + "PkgPath": "usr/local/lib/python3.11/site-packages/setuptools-65.5.1-py3.11.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@65.5.1", + "UID": "9bb97bbc4162777a" + }, + "InstalledVersion": "65.5.1", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:820a6f9168d48d4185407b307ea0bfe7fa7404c20bbacb33d99879cd94b3d41c", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:13578", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/9/ALSA-2025-13578.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + }, + { + "VulnerabilityID": "CVE-2022-32149", + "VendorIDs": [ + "GHSA-69ch-w2m2-3vjp", + "GO-2022-1059" + ], + "PkgID": "golang.org/x/text@v0.3.7", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.3.7", + "UID": "a0731065a426a72a" + }, + "InstalledVersion": "v0.3.7", + "FixedVersion": "0.3.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-32149", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1b9fa73a89e12b605f612b53bb39ff36feb99254ea57a30b9346f33d3f621c2a", + "Title": "golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags", + "Description": "An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-772" + ], + "VendorSeverity": { + "azure": 3, + "cbl-mariner": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-32149", + "https://github.com/golang/text/commit/434eadcdbc3b0256971992e8c70027278364c72c%20%28v0.3.8%29", + "https://go.dev/cl/442235", + "https://go.dev/issue/56152", + "https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ", + "https://groups.google.com/g/golang-dev/c/qfPIly0X7aU", + "https://nvd.nist.gov/vuln/detail/CVE-2022-32149", + "https://pkg.go.dev/vuln/GO-2022-1059", + "https://security.netapp.com/advisory/ntap-20230203-0006/", + "https://ubuntu.com/security/notices/USN-5873-1", + "https://www.cve.org/CVERecord?id=CVE-2022-32149" + ], + "PublishedDate": "2022-10-14T15:15:34.543Z", + "LastModifiedDate": "2026-06-17T04:46:45.967Z" + }, + { + "VulnerabilityID": "CVE-2026-56852", + "VendorIDs": [ + "GO-2026-5970" + ], + "PkgID": "golang.org/x/text@v0.3.7", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.3.7", + "UID": "a0731065a426a72a" + }, + "InstalledVersion": "v0.3.7", + "FixedVersion": "0.39.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56852", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:67ccd22eb4b3ab004788dff59bca154ede9e1d8e9078a07aa01f4a2d8a934f58", + "Title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input", + "Description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56852", + "https://go.dev/cl/794100", + "https://go.dev/issue/80142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56852", + "https://pkg.go.dev/vuln/GO-2026-5970", + "https://www.cve.org/CVERecord?id=CVE-2026-56852" + ], + "PublishedDate": "2026-07-21T20:17:02.867Z", + "LastModifiedDate": "2026-07-23T18:27:48.877Z" + }, + { + "VulnerabilityID": "CVE-2022-23806", + "VendorIDs": [ + "GO-2021-0319" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.14, 1.17.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23806", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d7dc34ef3eb2b712ae73559294cc6ad0be4e4774c0101e1ff8337549bcc05b6c", + "Title": "golang: crypto/elliptic: IsOnCurve returns true for invalid field elements", + "Description": "Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-252" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V3Score": 9.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V2Score": 6.4, + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2022-23806", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/382455", + "https://go.dev/issue/50974", + "https://go.googlesource.com/go/+/7f9494c277a471f6f47f4af3036285c0b1419816", + "https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ", + "https://linux.oracle.com/cve/CVE-2022-23806.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23806", + "https://pkg.go.dev/vuln/GO-2021-0319", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220225-0006/", + "https://www.cve.org/CVERecord?id=CVE-2022-23806", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-02-11T01:15:07.747Z", + "LastModifiedDate": "2026-06-17T04:30:48.69Z" + }, + { + "VulnerabilityID": "CVE-2023-24538", + "VendorIDs": [ + "GO-2023-1703" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24538", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4635b5741667482959e38e25a1bf00d11f77ec90341c3069970d01b62697d119", + "Title": "golang: html/template: backticks not treated as string delimiters", + "Description": "Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. \"var a = {{.}}\"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24538", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/20374d1d759bc4e17486bde1cb9dca5be37d9e52%20%28go1.20.3%29", + "https://github.com/golang/go/commit/b1e3ecfa06b67014429a197ec5e134ce4303ad9b%20%28go1.19.8%29", + "https://github.com/golang/go/issues/59234", + "https://go.dev/cl/482079", + "https://go.dev/issue/59234", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24538.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24538", + "https://pkg.go.dev/vuln/GO-2023-1703", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241115-0007/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24538" + ], + "PublishedDate": "2023-04-06T16:15:07.8Z", + "LastModifiedDate": "2026-06-17T05:39:29.67Z" + }, + { + "VulnerabilityID": "CVE-2023-24540", + "VendorIDs": [ + "GO-2023-1752" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24540", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:be94635bbca02b59287c9c91e529bb69644beddeddbf98928976d643700f8917", + "Title": "golang: html/template: improper handling of JavaScript whitespace", + "Description": "Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set \"\\t\\n\\f\\r\\u0020\\u2028\\u2029\" in JavaScript contexts that also contain actions may not be properly sanitized during execution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-77" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24540", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/4a28cad66655ee01c6e944271e23c33cab021765%20%28go1.20.4%29", + "https://github.com/golang/go/commit/ce7bd33345416e6d8cac901792060591cafc2797%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59721", + "https://go.dev/cl/491616", + "https://go.dev/issue/59721", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-24540.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24540", + "https://pkg.go.dev/vuln/GO-2023-1752", + "https://security.netapp.com/advisory/ntap-20241115-0008/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24540" + ], + "PublishedDate": "2023-05-11T16:15:09.687Z", + "LastModifiedDate": "2026-06-17T05:39:30.007Z" + }, + { + "VulnerabilityID": "CVE-2024-24790", + "VendorIDs": [ + "GO-2024-2887" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.21.11, 1.22.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-24790", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ae2c940d3762a9cc4464a4da78d4fe2dd0d116328a08c978dba9407fc468d9a8", + "Title": "golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses", + "Description": "The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.", + "Severity": "CRITICAL", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "bottlerocket": 2, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.7 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "http://www.openwall.com/lists/oss-security/2024/06/04/1", + "https://access.redhat.com/errata/RHSA-2025:7256", + "https://access.redhat.com/security/cve/CVE-2024-24790", + "https://bugzilla.redhat.com/2237777", + "https://bugzilla.redhat.com/2237778", + "https://bugzilla.redhat.com/2279814", + "https://bugzilla.redhat.com/2292787", + "https://bugzilla.redhat.com/2295310", + "https://bugzilla.redhat.com/2315719", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2279814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2292787", + "https://bugzilla.redhat.com/show_bug.cgi?id=2295310", + "https://bugzilla.redhat.com/show_bug.cgi?id=2315719", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24788", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24791", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9355", + "https://errata.almalinux.org/9/ALSA-2025-7256.html", + "https://errata.rockylinux.org/RLSA-2025:7256", + "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/2.9.0/BRSA-glvb5gspjgq6.toml", + "https://github.com/golang/go/commit/051bdf3fd12a40307606ff9381138039c5f452f0%20%281.21%29", + "https://github.com/golang/go/commit/12d5810cdb1f73cf23d7a86462143e9463317fca%20%281.22%29", + "https://github.com/golang/go/issues/67680", + "https://go.dev/cl/590316", + "https://go.dev/issue/67680", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ", + "https://linux.oracle.com/cve/CVE-2024-24790.html", + "https://linux.oracle.com/errata/ELSA-2025-7256.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-24790", + "https://pkg.go.dev/vuln/GO-2024-2887", + "https://security.netapp.com/advisory/ntap-20240905-0002/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2024-24790" + ], + "PublishedDate": "2024-06-05T16:15:10.56Z", + "LastModifiedDate": "2026-06-17T07:14:52.097Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e03406433401c607d4d8df576a785aedd54f27e93734b87a1ceda83ef20b5901", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2021-39293", + "VendorIDs": [ + "GO-2022-0273" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.8, 1.17.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-39293", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2ebc8385c45e2441ed9082825032df51b82f69f8b0e819351df5102678b4e478", + "Title": "golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196)", + "Description": "In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-39293", + "https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/343434", + "https://go.dev/issue/47801", + "https://go.googlesource.com/go/+/bacbc33439b124ffd7392c91a5f5d96eca8c0c0b", + "https://groups.google.com/g/golang-announce/c/dx9d7IOseHw", + "https://linux.oracle.com/cve/CVE-2021-39293.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-39293", + "https://pkg.go.dev/vuln/GO-2022-0273", + "https://security.netapp.com/advisory/ntap-20220217-0009/", + "https://www.cve.org/CVERecord?id=CVE-2021-39293" + ], + "PublishedDate": "2022-01-24T01:15:07.92Z", + "LastModifiedDate": "2026-06-17T04:03:28.747Z" + }, + { + "VulnerabilityID": "CVE-2021-41771", + "VendorIDs": [ + "GO-2021-0263" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.10, 1.17.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-41771", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a3df0a8b3e947b41e2ef1e0b3a5511b79c7de8115974fb2e05d485fc64e8fd57", + "Title": "golang: debug/macho: invalid dynamic symbol table command can cause panic", + "Description": "ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-119" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-41771", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/367075", + "https://go.dev/issue/48990", + "https://go.googlesource.com/go/+/61536ec03063b4951163bd09609c86d82631fa27", + "https://groups.google.com/g/golang-announce/c/0fM21h43arc", + "https://linux.oracle.com/cve/CVE-2021-41771.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4OFS3M3OFB24SWPTIAPARKGPUMQVUY6Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ON7BQRRJZBOR5TJHURBAB3WLF4YXFC6Z/", + "https://nvd.nist.gov/vuln/detail/CVE-2021-41771", + "https://pkg.go.dev/vuln/GO-2021-0263", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20211210-0003/", + "https://www.cve.org/CVERecord?id=CVE-2021-41771", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-11-08T06:15:08.057Z", + "LastModifiedDate": "2026-06-17T04:08:53.673Z" + }, + { + "VulnerabilityID": "CVE-2021-41772", + "VendorIDs": [ + "GO-2021-0264" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.10, 1.17.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-41772", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:73d00b9ea41fb0f588935d44423a2f8976406679d3c39efe16d27ce709805ba2", + "Title": "golang: archive/zip: Reader.Open panics on empty string", + "Description": "Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-41772", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/349770", + "https://go.dev/issue/48085", + "https://go.googlesource.com/go/+/b24687394b55a93449e2be4e6892ead58ea9a10f", + "https://groups.google.com/g/golang-announce/c/0fM21h43arc", + "https://linux.oracle.com/cve/CVE-2021-41772.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4OFS3M3OFB24SWPTIAPARKGPUMQVUY6Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ON7BQRRJZBOR5TJHURBAB3WLF4YXFC6Z/", + "https://nvd.nist.gov/vuln/detail/CVE-2021-41772", + "https://pkg.go.dev/vuln/GO-2021-0264", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20211210-0003/", + "https://www.cve.org/CVERecord?id=CVE-2021-41772", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-11-08T06:15:08.107Z", + "LastModifiedDate": "2026-06-17T04:08:53.8Z" + }, + { + "VulnerabilityID": "CVE-2021-44716", + "VendorIDs": [ + "GHSA-vc3p-29h2-gpcp", + "GO-2022-0288" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.12, 1.17.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-44716", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:eaa4c5065bc85b5431b8123080eab7ee06cd20c09313e049bd3e9a298e237e18", + "Title": "golang: net/http: limit growth of header canonicalization cache", + "Description": "net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:0001", + "https://access.redhat.com/security/cve/CVE-2021-44716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2030801", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44716", + "https://errata.rockylinux.org/RLSA-2022:0001", + "https://github.com/golang/go/commit/48d948963c5ce7add72af5665a871caff6c1d35a%20%28go1.17.5%29", + "https://github.com/golang/net/commit/491a49abca63de5e07ef554052d180a1b5fe2d70", + "https://go.dev/cl/369794", + "https://go.dev/issue/50058", + "https://groups.google.com/g/golang-announce/c/hcmEScgc00k", + "https://groups.google.com/g/golang-announce/c/hcmEScgc00k/m/ZWnOjeY4CQAJ", + "https://linux.oracle.com/cve/CVE-2021-44716.html", + "https://linux.oracle.com/errata/ELSA-2022-0001.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-44716", + "https://pkg.go.dev/vuln/GO-2022-0288", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220121-0002/", + "https://www.cve.org/CVERecord?id=CVE-2021-44716" + ], + "PublishedDate": "2022-01-01T05:15:08.307Z", + "LastModifiedDate": "2026-06-17T04:12:45.48Z" + }, + { + "VulnerabilityID": "CVE-2022-23772", + "VendorIDs": [ + "GO-2021-0317" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.14, 1.17.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23772", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e712c8bd09bc0bfa6066cd07c213fb0b33a138ac97430f866616d957a01ed784", + "Title": "golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString", + "Description": "Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:C", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 7.8, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2022-23772", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/379537", + "https://go.dev/issue/50699", + "https://go.googlesource.com/go/+/ad345c265916bbf6c646865e4642eafce6d39e78", + "https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ", + "https://linux.oracle.com/cve/CVE-2022-23772.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23772", + "https://pkg.go.dev/vuln/GO-2021-0317", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220225-0006/", + "https://www.cve.org/CVERecord?id=CVE-2022-23772", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-02-11T01:15:07.657Z", + "LastModifiedDate": "2026-06-17T04:30:46.407Z" + }, + { + "VulnerabilityID": "CVE-2022-24675", + "VendorIDs": [ + "GO-2022-0433" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.9, 1.18.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-24675", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f4f5b16f7f71ef9d28f3da7054db0af14279b09fc9e174bf7e7640914596916c", + "Title": "golang: encoding/pem: fix stack overflow in Decode", + "Description": "encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-24675", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/399820", + "https://go.dev/issue/51853", + "https://go.googlesource.com/go/+/45c3387d777caf28f4b992ad9a6216e3085bb8fe", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/oecdBNLOml8", + "https://linux.oracle.com/cve/CVE-2022-24675.html", + "https://linux.oracle.com/errata/ELSA-2022-5337.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TYZC4OAY54TO75FBEFAPV5G7O4D5TM/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F3BMW5QGX53CMIJIZWKXFKBJX2C5GWTY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RCRSABD6CUDIZULZPZL5BJ3ET3A2NEJP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-24675", + "https://pkg.go.dev/vuln/GO-2022-0433", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220915-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-24675" + ], + "PublishedDate": "2022-04-20T10:15:07.93Z", + "LastModifiedDate": "2026-06-17T04:32:16.51Z" + }, + { + "VulnerabilityID": "CVE-2022-24921", + "VendorIDs": [ + "GO-2021-0347" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.15, 1.17.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-24921", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2effe5876274bd48fffa149fd806693b204b3006edc2d5bc33d552ccdbd3bf90", + "Title": "golang: regexp: stack exhaustion via a deeply nested expression", + "Description": "regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-24921", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/384616", + "https://go.dev/issue/51112", + "https://go.googlesource.com/go/+/452f24ae94f38afa3704d4361d91d51218405c0a", + "https://groups.google.com/g/golang-announce/c/RP1hfrBYVuk", + "https://linux.oracle.com/cve/CVE-2022-24921.html", + "https://linux.oracle.com/errata/ELSA-2022-9363.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-24921", + "https://pkg.go.dev/vuln/GO-2021-0347", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220325-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-24921" + ], + "PublishedDate": "2022-03-05T20:15:08.323Z", + "LastModifiedDate": "2026-06-17T04:32:47.957Z" + }, + { + "VulnerabilityID": "CVE-2022-27664", + "VendorIDs": [ + "GHSA-69cg-p879-7622", + "GO-2022-0969" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.6, 1.19.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-27664", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1dffc29ee32bcbb42fdcbd55d80b8949c44e4cd6d22f3bca70395b0e7f9b01be", + "Title": "golang: net/http: handle server errors after sending GOAWAY", + "Description": "In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:2177", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-27664", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2124669", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27664", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2023:2177", + "https://github.com/golang/go/commit/5bc9106458fc07851ac324a4157132a91b1f3479%20%28go1.18.6%29", + "https://github.com/golang/go/commit/9cfe4e258b1c9d4a04a42539c21c7bdb2e227824%20%28go1.19.1%29", + "https://github.com/golang/go/issues/54658", + "https://go.dev/cl/428735", + "https://go.dev/issue/54658", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s", + "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s/m/0tgO0pjiBQAJ", + "https://linux.oracle.com/cve/CVE-2022-27664.html", + "https://linux.oracle.com/errata/ELSA-2024-0121.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-27664", + "https://pkg.go.dev/vuln/GO-2022-0969", + "https://security.gentoo.org/glsa/202209-26", + "https://security.netapp.com/advisory/ntap-20220923-0004/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-8089-1", + "https://ubuntu.com/security/notices/USN-8089-2", + "https://ubuntu.com/security/notices/USN-8089-3", + "https://www.cve.org/CVERecord?id=CVE-2022-27664" + ], + "PublishedDate": "2022-09-06T18:15:12.747Z", + "LastModifiedDate": "2026-06-17T04:37:26.873Z" + }, + { + "VulnerabilityID": "CVE-2022-28131", + "VendorIDs": [ + "GO-2022-0521" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-28131", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0288aaa8eadc514fe494a25f3970b9199d18d52113b9d98512a4280f819997b5", + "Title": "golang: encoding/xml: stack exhaustion in Decoder.Skip", + "Description": "Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8057", + "https://access.redhat.com/security/cve/CVE-2022-28131", + "https://bugzilla.redhat.com/2044628", + "https://bugzilla.redhat.com/2045880", + "https://bugzilla.redhat.com/2050648", + "https://bugzilla.redhat.com/2050742", + "https://bugzilla.redhat.com/2050743", + "https://bugzilla.redhat.com/2065290", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107376", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2107390", + "https://bugzilla.redhat.com/2107392", + "https://bugzilla.redhat.com/show_bug.cgi?id=2044628", + "https://bugzilla.redhat.com/show_bug.cgi?id=2045880", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050648", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050742", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2055349", + "https://bugzilla.redhat.com/show_bug.cgi?id=2065290", + "https://bugzilla.redhat.com/show_bug.cgi?id=2104367", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23648", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21698", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21702", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21713", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2022-8057.html", + "https://errata.rockylinux.org/RLSA-2022:8057", + "https://github.com/golang/go/commit/90f040ec510dd678b7860d70ca77e5682f4c7e96", + "https://go.dev/cl/417062", + "https://go.dev/issue/53614", + "https://go.googlesource.com/go/+/08c46ed43d80bbb67cb904944ea3417989be4af3", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-28131.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-28131", + "https://pkg.go.dev/vuln/GO-2022-0521", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-28131" + ], + "PublishedDate": "2022-08-10T20:15:32.767Z", + "LastModifiedDate": "2026-06-17T04:38:02.23Z" + }, + { + "VulnerabilityID": "CVE-2022-28327", + "VendorIDs": [ + "GO-2022-0435" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.9, 1.18.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-28327", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6c7df270cc4c927bfd008bec724b08ff7ccffd4db90741bf9982015f2a3fb26e", + "Title": "golang: crypto/elliptic: panic caused by oversized scalar", + "Description": "The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-28327", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/397135", + "https://go.dev/issue/52075", + "https://go.googlesource.com/go/+/37065847d87df92b5eb246c88ba2085efcf0b331", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/oecdBNLOml8", + "https://linux.oracle.com/cve/CVE-2022-28327.html", + "https://linux.oracle.com/errata/ELSA-2022-5337.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TYZC4OAY54TO75FBEFAPV5G7O4D5TM/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F3BMW5QGX53CMIJIZWKXFKBJX2C5GWTY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NY6GEAJMNKKMU5H46QO4D7D6A24KSPXE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RCRSABD6CUDIZULZPZL5BJ3ET3A2NEJP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-28327", + "https://pkg.go.dev/vuln/GO-2022-0435", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220915-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-28327" + ], + "PublishedDate": "2022-04-20T10:15:08.03Z", + "LastModifiedDate": "2026-06-17T04:38:23.653Z" + }, + { + "VulnerabilityID": "CVE-2022-2879", + "VendorIDs": [ + "GO-2022-1037" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-2879", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6ccfd6bde21af7ce771cca6c5d22e144c0c7ee4241f5535d878ce9e5c6b14d9b", + "Title": "golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers", + "Description": "Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2204", + "https://access.redhat.com/security/cve/CVE-2022-2879", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132867", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2204.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/0a723816cd205576945fa57fbdde7e6532d59d08%20%28go1.18.7%29", + "https://github.com/golang/go/commit/4fa773cdefd20be093c84f731be7d4febf5536fa%20%28go1.19.2%29", + "https://github.com/golang/go/issues/54853", + "https://github.com/vbatts/tar-split/releases/tag/v0.12.1", + "https://go.dev/cl/439355", + "https://go.dev/issue/54853", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-2879.html", + "https://linux.oracle.com/errata/ELSA-2024-2988.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-2879", + "https://pkg.go.dev/vuln/GO-2022-1037", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-2879" + ], + "PublishedDate": "2022-10-14T15:15:17.647Z", + "LastModifiedDate": "2026-06-17T04:42:45.443Z" + }, + { + "VulnerabilityID": "CVE-2022-2880", + "VendorIDs": [ + "GO-2022-1038" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-2880", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b2f8f18ba35b83720ed4815afad9a92004c1929063ed427f5534198a51aa1c6c", + "Title": "golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters", + "Description": "Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-444" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-2880", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/9d2c73a9fd69e45876509bb3bdb2af99bf77da1e%20%28go1.18.7%29", + "https://github.com/golang/go/commit/f6d844510d5f1e3b3098eba255d9b633d45eac3b%20%28go1.19.2%29", + "https://github.com/golang/go/issues/54663", + "https://go.dev/cl/432976", + "https://go.dev/issue/54663", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-2880.html", + "https://linux.oracle.com/errata/ELSA-2024-3254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-2880", + "https://pkg.go.dev/vuln/GO-2022-1038", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-2880" + ], + "PublishedDate": "2022-10-14T15:15:18.09Z", + "LastModifiedDate": "2026-06-17T04:42:45.547Z" + }, + { + "VulnerabilityID": "CVE-2022-29804", + "VendorIDs": [ + "GO-2022-0533" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-29804", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:420313aec995a767227ad30ec48d3d479acd52cee6435c81ae6c087b5e8a1af2", + "Title": "ELSA-2022-17957: ol8addon security update (IMPORTANT)", + "Description": "Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/401595", + "https://go.dev/issue/52476", + "https://go.googlesource.com/go/+/9cd1818a7d019c02fa4898b3e45a323e35033290", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-29804.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-29804", + "https://pkg.go.dev/vuln/GO-2022-0533" + ], + "PublishedDate": "2022-08-10T20:15:34.89Z", + "LastModifiedDate": "2026-06-17T04:40:44.503Z" + }, + { + "VulnerabilityID": "CVE-2022-30580", + "VendorIDs": [ + "GO-2022-0532" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30580", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a710d0fc330493c82b0801c73e884d16697a27829a648b5f745379144f417a95", + "Title": "golang: os/exec: Code injection in Cmd.Start", + "Description": "Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either \"..com\" or \"..exe\" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-30580", + "https://go.dev/cl/403759", + "https://go.dev/issue/52574", + "https://go.googlesource.com/go/+/960ffa98ce73ef2c2060c84c7ac28d37a83f345e", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-30580.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30580", + "https://pkg.go.dev/vuln/GO-2022-0532", + "https://www.cve.org/CVERecord?id=CVE-2022-30580" + ], + "PublishedDate": "2022-08-10T20:15:40.227Z", + "LastModifiedDate": "2026-06-17T04:43:53.69Z" + }, + { + "VulnerabilityID": "CVE-2022-30630", + "VendorIDs": [ + "GO-2022-0527" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30630", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:739894263eccb643ca3433b8e192d0452810de0ffcd1c0393019e096048f7664", + "Title": "golang: io/fs: stack exhaustion in Glob", + "Description": "Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30630", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/315e80d293b684ac2902819e58f618f1b5a14d49%20%281.18%29", + "https://go.dev/cl/417065", + "https://go.dev/issue/53415", + "https://go.googlesource.com/go/+/fa2d41d0ca736f3ad6b200b2a4e134364e9acc59", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30630.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30630", + "https://pkg.go.dev/vuln/GO-2022-0527", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30630" + ], + "PublishedDate": "2022-08-10T20:15:40.977Z", + "LastModifiedDate": "2026-06-17T04:43:58.727Z" + }, + { + "VulnerabilityID": "CVE-2022-30631", + "VendorIDs": [ + "GO-2022-0524" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30631", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3648dbddd0a329b967b9322d04bc47fcc7f5ff7edbf886efc9640fdc31439c3d", + "Title": "golang: compress/gzip: stack exhaustion in Reader.Read", + "Description": "Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30631", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/8e27a8ac4c001c27713810b75925aa3794049c48%20%281.18%29", + "https://go.dev/cl/417067", + "https://go.dev/issue/53168", + "https://go.googlesource.com/go/+/b2b8872c876201eac2d0707276c6999ff3eb185e", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30631.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30631", + "https://pkg.go.dev/vuln/GO-2022-0524", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30631" + ], + "PublishedDate": "2022-08-10T20:15:41.373Z", + "LastModifiedDate": "2026-06-17T04:43:58.893Z" + }, + { + "VulnerabilityID": "CVE-2022-30632", + "VendorIDs": [ + "GO-2022-0522" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30632", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6784c69a4c681fec6e8fc9078d7c203ff97f8ebf96a095438589e29859ba6a61", + "Title": "golang: path/filepath: stack exhaustion in Glob", + "Description": "Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30632", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/5ebd862b1714dad1544bd10a24c47cdb53ad7f46%20%281.18%29", + "https://go.dev/cl/417066", + "https://go.dev/issue/53416", + "https://go.googlesource.com/go/+/ac68c6c683409f98250d34ad282b9e1b0c9095ef", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30632.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30632", + "https://pkg.go.dev/vuln/GO-2022-0522", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30632" + ], + "PublishedDate": "2022-08-10T20:15:41.877Z", + "LastModifiedDate": "2026-06-17T04:43:59.057Z" + }, + { + "VulnerabilityID": "CVE-2022-30633", + "VendorIDs": [ + "GO-2022-0523" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30633", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:41f94859d965c0b559a388691b08fd9f78c7983318296a749b10f9bf73f7eb19", + "Title": "golang: encoding/xml: stack exhaustion in Unmarshal", + "Description": "Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8057", + "https://access.redhat.com/security/cve/CVE-2022-30633", + "https://bugzilla.redhat.com/2044628", + "https://bugzilla.redhat.com/2045880", + "https://bugzilla.redhat.com/2050648", + "https://bugzilla.redhat.com/2050742", + "https://bugzilla.redhat.com/2050743", + "https://bugzilla.redhat.com/2065290", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107376", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2107390", + "https://bugzilla.redhat.com/2107392", + "https://bugzilla.redhat.com/show_bug.cgi?id=2044628", + "https://bugzilla.redhat.com/show_bug.cgi?id=2045880", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050648", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050742", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2055349", + "https://bugzilla.redhat.com/show_bug.cgi?id=2065290", + "https://bugzilla.redhat.com/show_bug.cgi?id=2104367", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23648", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21698", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21702", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21713", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2022-8057.html", + "https://errata.rockylinux.org/RLSA-2022:8057", + "https://github.com/golang/go/commit/2924ced71d16297320e8ff18829c2038e6ad8d9b%20%281.18%29", + "https://go.dev/cl/417061", + "https://go.dev/issue/53611", + "https://go.googlesource.com/go/+/c4c1993fd2a5b26fe45c09592af6d3388a3b2e08", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30633.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30633", + "https://pkg.go.dev/vuln/GO-2022-0523", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30633" + ], + "PublishedDate": "2022-08-10T20:15:42.21Z", + "LastModifiedDate": "2026-06-17T04:43:59.163Z" + }, + { + "VulnerabilityID": "CVE-2022-30634", + "VendorIDs": [ + "GO-2022-0477" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30634", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:379f0439de4c93187a851dafede3973998d1a1608b624e7c9cc4297a26392805", + "Title": "ELSA-2022-17957: ol8addon security update (IMPORTANT)", + "Description": "Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/402257", + "https://go.dev/issue/52561", + "https://go.googlesource.com/go/+/bb1f4416180511231de6d17a1f2f55c82aafc863", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-30634.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30634", + "https://pkg.go.dev/vuln/GO-2022-0477" + ], + "PublishedDate": "2022-07-15T20:15:08.597Z", + "LastModifiedDate": "2026-06-17T04:43:59.317Z" + }, + { + "VulnerabilityID": "CVE-2022-30635", + "VendorIDs": [ + "GO-2022-0526" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30635", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0eab7f42cf1669888b4ab3f81ef4e9180fb760dfb459c7b8590db57c37c9a6ad", + "Title": "golang: encoding/gob: stack exhaustion in Decoder.Decode", + "Description": "Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-30635", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/fb979a50823e5a0575cf6166b3f17a13364cbf81%20%281.18%29", + "https://go.dev/cl/417064", + "https://go.dev/issue/53615", + "https://go.googlesource.com/go/+/6fa37e98ea4382bf881428ee0c150ce591500eb7", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30635.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30635", + "https://pkg.go.dev/vuln/GO-2022-0526", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30635" + ], + "PublishedDate": "2022-08-10T20:15:42.64Z", + "LastModifiedDate": "2026-06-17T04:43:59.43Z" + }, + { + "VulnerabilityID": "CVE-2022-32189", + "VendorIDs": [ + "GO-2022-0537" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.13, 1.18.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-32189", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:090ae0abb232e4edd1bd455afd50d5cd26cb39e343f189c20114fdeeb571665f", + "Title": "golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service", + "Description": "A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 1, + "rocky": 1, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:7950", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-32189", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2059869", + "https://bugzilla.redhat.com/show_bug.cgi?id=2059870", + "https://bugzilla.redhat.com/show_bug.cgi?id=2060061", + "https://bugzilla.redhat.com/show_bug.cgi?id=2062597", + "https://bugzilla.redhat.com/show_bug.cgi?id=2064087", + "https://bugzilla.redhat.com/show_bug.cgi?id=2088459", + "https://bugzilla.redhat.com/show_bug.cgi?id=2105961", + "https://bugzilla.redhat.com/show_bug.cgi?id=2110864", + "https://bugzilla.redhat.com/show_bug.cgi?id=2113814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2118831", + "https://bugzilla.redhat.com/show_bug.cgi?id=2123055", + "https://bugzilla.redhat.com/show_bug.cgi?id=2123210", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32189", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2022:7950", + "https://github.com/golang/go/commit/9240558e4f342fc6e98fec22de17c04b45089349%20%281.18%29", + "https://go.dev/cl/417774", + "https://go.dev/issue/53871", + "https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66", + "https://groups.google.com/g/golang-announce/c/YqYYG87xB10", + "https://groups.google.com/g/golang-nuts/c/DCFSyTGM0wU", + "https://linux.oracle.com/cve/CVE-2022-32189.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-32189", + "https://pkg.go.dev/vuln/GO-2022-0537", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-32189" + ], + "PublishedDate": "2022-08-10T20:15:47.507Z", + "LastModifiedDate": "2026-06-17T04:46:49.81Z" + }, + { + "VulnerabilityID": "CVE-2022-41715", + "VendorIDs": [ + "GO-2022-1039" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41715", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c974d3241d262d2e457bbd33ddb604178b55deac6c969003950eec9cbfb416e4", + "Title": "golang: regexp/syntax: limit memory used by parsing regexps", + "Description": "Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2592", + "https://access.redhat.com/security/cve/CVE-2022-41715", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2592.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/645abfe529dc325e16daa17210640c2907d1c17a%20%28go1.19.2%29", + "https://github.com/golang/go/commit/e9017c2416ad0ef642f5e0c2eab2dbf3cba4d997%20%28go1.18.7%29", + "https://github.com/golang/go/issues/55949", + "https://go.dev/cl/439356", + "https://go.dev/issue/55949", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-41715.html", + "https://linux.oracle.com/errata/ELSA-2024-3254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41715", + "https://pkg.go.dev/vuln/GO-2022-1039", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41715" + ], + "PublishedDate": "2022-10-14T15:16:20.78Z", + "LastModifiedDate": "2026-06-17T05:03:41.893Z" + }, + { + "VulnerabilityID": "CVE-2022-41716", + "VendorIDs": [ + "GO-2022-1095" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.8, 1.19.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41716", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7696141e6b642f5c62039161e1d421a50f08ea879219196c2d5645064b188369", + "Title": "Due to unsanitized NUL values, attackers may be able to maliciously se ...", + "Description": "Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string \"A=B\\x00C=D\" sets the variables \"A=B\" and \"C=D\".", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/446916", + "https://go.dev/issue/56284", + "https://groups.google.com/g/golang-announce/c/mbHY1UY3BaM/m/hSpmRzk-AgAJ", + "https://linux.oracle.com/cve/CVE-2022-41716.html", + "https://linux.oracle.com/errata/ELSA-2023-18908.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41716", + "https://pkg.go.dev/vuln/GO-2022-1095", + "https://security.netapp.com/advisory/ntap-20230120-0007/" + ], + "PublishedDate": "2022-11-02T16:15:11.15Z", + "LastModifiedDate": "2026-06-17T05:03:41.997Z" + }, + { + "VulnerabilityID": "CVE-2022-41720", + "VendorIDs": [ + "GO-2022-1143" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.9, 1.19.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41720", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8b6c93f814c173eb6e98a0e682a861206ff18b77ca5cfa4190cab7dd0498367d", + "Title": "golang: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows", + "Description": "On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS(\"C:/tmp\").Open(\"COM1\") opens the COM1 device. Both os.DirFS and http.Dir only provide read-only filesystem access. In addition, on Windows, an os.DirFS for the directory (the root of the current drive) can permit a maliciously crafted path to escape from the drive and access any path on the system. With fix applied, the behavior of os.DirFS(\"\") has changed. Previously, an empty root was treated equivalently to \"/\", so os.DirFS(\"\").Open(\"tmp\") would open the path \"/tmp\". This now returns an error.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-41720", + "https://go.dev/cl/455716", + "https://go.dev/issue/56694", + "https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ", + "https://linux.oracle.com/cve/CVE-2022-41720.html", + "https://linux.oracle.com/errata/ELSA-2023-18908.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41720", + "https://pkg.go.dev/vuln/GO-2022-1143", + "https://www.cve.org/CVERecord?id=CVE-2022-41720" + ], + "PublishedDate": "2022-12-07T17:15:10.293Z", + "LastModifiedDate": "2026-06-17T05:03:42.497Z" + }, + { + "VulnerabilityID": "CVE-2022-41722", + "VendorIDs": [ + "GO-2023-1568" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41722", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d720063b6563b665026f8c0041333acc6c06f3520360d0b71562d9e92e4583e1", + "Title": "golang: path/filepath: path-filepath filepath.Clean path traversal", + "Description": "A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as \"a/../c:/b\" into the valid path \"c:\\b\". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path \".\\c:\\b\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-41722", + "https://go.dev/cl/468123", + "https://go.dev/issue/57274", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41722", + "https://pkg.go.dev/vuln/GO-2023-1568", + "https://www.cve.org/CVERecord?id=CVE-2022-41722" + ], + "PublishedDate": "2023-02-28T18:15:09.887Z", + "LastModifiedDate": "2026-06-17T05:03:42.79Z" + }, + { + "VulnerabilityID": "CVE-2022-41723", + "VendorIDs": [ + "GHSA-vvpx-j8f3-3w6h", + "GO-2023-1571" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41723", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9873688725e97e393727a7efc0dae6029d15888e81680da51093593f7f7f98f7", + "Title": "golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding", + "Description": "A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41723", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/advisories/GHSA-vvpx-j8f3-3w6h", + "https://go.dev/cl/468135", + "https://go.dev/cl/468295", + "https://go.dev/issue/57855", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41723.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MA5XS5DAOJ5PKKNG5TUXKPQOFHT5VBC/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGW7GE2Z32ZT47UFAQFDRQE33B7Q7LMT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41723", + "https://pkg.go.dev/vuln/GO-2023-1571", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230331-0010/", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://ubuntu.com/security/notices/USN-8089-1", + "https://ubuntu.com/security/notices/USN-8089-2", + "https://ubuntu.com/security/notices/USN-8089-3", + "https://vuln.go.dev/ID/GO-2023-1571.json", + "https://www.couchbase.com/alerts/", + "https://www.cve.org/CVERecord?id=CVE-2022-41723" + ], + "PublishedDate": "2023-02-28T18:15:09.98Z", + "LastModifiedDate": "2026-06-17T05:03:42.9Z" + }, + { + "VulnerabilityID": "CVE-2022-41724", + "VendorIDs": [ + "GO-2023-1570" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41724", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e51f1c7d7dd2e7d4b1b9cd713ba439c44b4491f50af3eaac06e93f8eb3ea2713", + "Title": "golang: crypto/tls: large handshake records may cause panics", + "Description": "Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41724", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://go.dev/cl/468125", + "https://go.dev/issue/58001", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41724.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41724", + "https://pkg.go.dev/vuln/GO-2023-1570", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41724" + ], + "PublishedDate": "2023-02-28T18:15:10.043Z", + "LastModifiedDate": "2026-06-17T05:03:43.11Z" + }, + { + "VulnerabilityID": "CVE-2022-41725", + "VendorIDs": [ + "GO-2023-1569" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41725", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:86486fa373c95be8b1b76ea17e59e8985d6c106c358e8b422992ae6f72da893a", + "Title": "golang: net/http, mime/multipart: denial of service from excessive resource consumption", + "Description": "A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing \"up to maxMemory bytes +10MB (reserved for non-file parts) in memory\". File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did not properly account for all memory consumed by a parsed form, such as map entry overhead, part names, and MIME headers, permitting a maliciously crafted form to consume well over 10MB. In addition, ReadForm contained no limit on the number of disk files created, permitting a relatively small request body to create a large number of disk temporary files. With fix, ReadForm now properly accounts for various forms of memory overhead, and should now stay within its documented limit of 10MB + maxMemory bytes of memory consumption. Users should still be aware that this limit is high and may still be hazardous. In addition, ReadForm now creates at most one on-disk temporary file, combining multiple form parts into a single temporary file. The mime/multipart.File interface type's documentation states, \"If stored on disk, the File's underlying concrete type will be an *os.File.\". This is no longer the case when a form contains more than one file part, due to this coalescing of parts into a single file. The previous behavior of using distinct files for each form part may be reenabled with the environment variable GODEBUG=multipartfiles=distinct. Users should be aware that multipart.ReadForm and the http.Request methods that call it do not limit the amount of disk consumed by temporary files. Callers can limit the size of form data with http.MaxBytesReader.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41725", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/5c55ac9bf1e5f779220294c843526536605f42ab%20%5B1.19%5D", + "https://go.dev/cl/468124", + "https://go.dev/issue/58006", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41725.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41725", + "https://pkg.go.dev/vuln/GO-2023-1569", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41725" + ], + "PublishedDate": "2023-02-28T18:15:10.12Z", + "LastModifiedDate": "2026-06-17T05:03:43.243Z" + }, + { + "VulnerabilityID": "CVE-2023-24534", + "VendorIDs": [ + "GO-2023-1704" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24534", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:588ee5bebf401f3141acdfbd767a12328bbf2943d1564b0a75d7239402d85e8f", + "Title": "golang: net/http, net/textproto: denial of service from excessive memory allocation", + "Description": "HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more memory than required to hold the parsed headers. An attacker can exploit this behavior to cause an HTTP server to allocate large amounts of memory from a small request, potentially leading to memory exhaustion and a denial of service. With fix, header parsing now correctly allocates only the memory required to hold parsed headers.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24534", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/3991f6c41c7dfd167e889234c0cf1d840475e93c%20%28go1.20.3%29", + "https://github.com/golang/go/commit/d6759e7a059f4208f07aa781402841d7ddaaef96%20%28go1.19.8%29", + "https://go.dev/cl/481994", + "https://go.dev/issue/58975", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24534.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24534", + "https://pkg.go.dev/vuln/GO-2023-1704", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230526-0007/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24534" + ], + "PublishedDate": "2023-04-06T16:15:07.657Z", + "LastModifiedDate": "2026-06-17T05:39:28.893Z" + }, + { + "VulnerabilityID": "CVE-2023-24536", + "VendorIDs": [ + "GO-2023-1705" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24536", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e2c99ed78393fc80aa7ffe6d33da810f6d7d1af294df406a9d935f15e60c8df0", + "Title": "golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption", + "Description": "Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems from several causes: 1. mime/multipart.Reader.ReadForm limits the total memory a parsed multipart form can consume. ReadForm can undercount the amount of memory consumed, leading it to accept larger inputs than intended. 2. Limiting total memory does not account for increased pressure on the garbage collector from large numbers of small allocations in forms with many parts. 3. ReadForm can allocate a large number of short-lived buffers, further increasing pressure on the garbage collector. The combination of these factors can permit an attacker to cause an program that parses multipart forms to consume large amounts of CPU and memory, potentially resulting in a denial of service. This affects programs that use mime/multipart.Reader.ReadForm, as well as form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. With fix, ReadForm now does a better job of estimating the memory consumption of parsed forms, and performs many fewer short-lived allocations. In addition, the fixed mime/multipart.Reader imposes the following limits on the size of parsed forms: 1. Forms parsed with ReadForm may contain no more than 1000 parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxparts=. 2. Form parts parsed with NextPart and NextRawPart may contain no more than 10,000 header fields. In addition, forms parsed with ReadForm may contain no more than 10,000 header fields across all parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxheaders=.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24536", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/7917b5f31204528ea72e0629f0b7d52b35b27538%20%28go.1.19.8%29", + "https://github.com/golang/go/commit/bf8c7c575c8a552d9d79deb29e80854dc88528d0%20%28go1.20.3%29", + "https://go.dev/cl/482075", + "https://go.dev/cl/482076", + "https://go.dev/cl/482077", + "https://go.dev/issue/59153", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24536.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24536", + "https://pkg.go.dev/vuln/GO-2023-1705", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230526-0007/", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24536" + ], + "PublishedDate": "2023-04-06T16:15:07.71Z", + "LastModifiedDate": "2026-06-17T05:39:29.287Z" + }, + { + "VulnerabilityID": "CVE-2023-24537", + "VendorIDs": [ + "GO-2023-1702" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24537", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:137b9ced7436c0515ed99f42f34ace50dab88fe34d0730aaaf980af789662575", + "Title": "golang: go/parser: Infinite loop in parsing", + "Description": "Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24537", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/126a1d02da82f93ede7ce0bd8d3c51ef627f2104%20%28go1.19.8%29", + "https://github.com/golang/go/commit/e7c4b07ecf6b367f1afc9cc48cde963829dd0aab%20%28go1.20.3%29", + "https://github.com/golang/go/issues/59180", + "https://go.dev/cl/482078", + "https://go.dev/issue/59180", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24537.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24537", + "https://pkg.go.dev/vuln/GO-2023-1702", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241129-0004/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24537" + ], + "PublishedDate": "2023-04-06T16:15:07.753Z", + "LastModifiedDate": "2026-06-17T05:39:29.483Z" + }, + { + "VulnerabilityID": "CVE-2023-24539", + "VendorIDs": [ + "GO-2023-1751" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24539", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:374dd101cdb71aadeee2097c8a2a3447701c48109cb1a3feb71af9ce240c94d8", + "Title": "golang: html/template: improper sanitization of CSS values", + "Description": "Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24539", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/090590fdccc8442728aa31601927da1bf2ef1288%20%28go1.20.4%29", + "https://github.com/golang/go/commit/e49282327b05192e46086bf25fd3ac691205fe80%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59720", + "https://go.dev/cl/491615", + "https://go.dev/issue/59720", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-24539.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24539", + "https://pkg.go.dev/vuln/GO-2023-1751", + "https://security.netapp.com/advisory/ntap-20241129-0005/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24539" + ], + "PublishedDate": "2023-05-11T16:15:09.6Z", + "LastModifiedDate": "2026-06-17T05:39:29.84Z" + }, + { + "VulnerabilityID": "CVE-2023-29400", + "VendorIDs": [ + "GO-2023-1753" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-29400", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7a1742cd0c8859f596e4c709dac6a819efd970e80a160f105e9ee5c065fb3965", + "Title": "golang: html/template: improper handling of empty HTML attributes", + "Description": "Templates containing actions in unquoted HTML attributes (e.g. \"attr={{.}}\") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-29400", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/337dd75343145b74ed2073d793322eb4103b56ad%20%28go1.20.4%29", + "https://github.com/golang/go/commit/9db0e74f606b8afb28cc71d4b1c8b4ed24cabbf5%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59722", + "https://go.dev/cl/491617", + "https://go.dev/issue/59722", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-29400.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-29400", + "https://pkg.go.dev/vuln/GO-2023-1753", + "https://security.netapp.com/advisory/ntap-20241213-0005/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-29400" + ], + "PublishedDate": "2023-05-11T16:15:09.85Z", + "LastModifiedDate": "2026-06-17T05:49:57.937Z" + }, + { + "VulnerabilityID": "CVE-2023-29403", + "VendorIDs": [ + "GO-2023-1840" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.10, 1.20.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-29403", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ad7ab3cc688c0e14e698b8e3499acc0aa2c6cdb4001e040b5be5c87c807260ea", + "Title": "golang: runtime: unexpected behavior of setuid/setgid binaries", + "Description": "On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-668" + ], + "VendorSeverity": { + "alma": 4, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 4, + "photon": 3, + "redhat": 3, + "rocky": 4, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:3923", + "https://access.redhat.com/security/cve/CVE-2023-29403", + "https://bugzilla.redhat.com/2216965", + "https://bugzilla.redhat.com/2217562", + "https://bugzilla.redhat.com/2217565", + "https://bugzilla.redhat.com/2217569", + "https://bugzilla.redhat.com/show_bug.cgi?id=2216965", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217562", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217565", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217569", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29402", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29403", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29404", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29405", + "https://errata.almalinux.org/9/ALSA-2023-3923.html", + "https://errata.rockylinux.org/RLSA-2023:3923", + "https://github.com/golang/go/commit/36144ba429ef2650940c72e7a0b932af3612d420%20%28go1.20.5%29", + "https://github.com/golang/go/commit/a7b1cd452ddc69a6606c2f35ac5786dc892e62cb%20%28go1.19.10%29", + "https://github.com/golang/go/issues/60272", + "https://go.dev/cl/501223", + "https://go.dev/issue/60272", + "https://groups.google.com/g/golang-announce/c/q5135a9d924", + "https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJ", + "https://linux.oracle.com/cve/CVE-2023-29403.html", + "https://linux.oracle.com/errata/ELSA-2023-3923.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZ2O6YCO2IZMZJELQGZYR2WAUNEDLYV6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XBS3IIK6ADV24C5ULQU55QLT2UE762ZX/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-29403", + "https://pkg.go.dev/vuln/GO-2023-1840", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241220-0009/", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2023-29403" + ], + "PublishedDate": "2023-06-08T21:15:16.927Z", + "LastModifiedDate": "2026-06-17T05:49:58.43Z" + }, + { + "VulnerabilityID": "CVE-2023-39325", + "VendorIDs": [ + "GHSA-4374-p667-p6c8", + "GO-2023-2102" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.10, 1.21.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-39325", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5e5b8428d3032a4811a8f482f7898b14748fea31017566c4077adece26a20216", + "Title": "golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)", + "Description": "A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "bottlerocket": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39325", + "https://access.redhat.com/errata/RHSA-2023:6077", + "https://access.redhat.com/security/cve/CVE-2023-39325", + "https://access.redhat.com/security/cve/CVE-2023-44487", + "https://bugzilla.redhat.com/2242803", + "https://bugzilla.redhat.com/2243296", + "https://bugzilla.redhat.com/show_bug.cgi?id=2242803", + "https://bugzilla.redhat.com/show_bug.cgi?id=2243296", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39325", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44487", + "https://errata.almalinux.org/9/ALSA-2023-6077.html", + "https://errata.rockylinux.org/RLSA-2023:6077", + "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-48vh-q3rp-4grw", + "https://github.com/golang/go/commit/24ae2d927285c697440fdde3ad7f26028354bcf3%20%5Bgolang-%201.21%5D", + "https://github.com/golang/go/commit/e175f27f58aa7b9cd4d79607ae65d2cd5baaee68%20%5Bgolang-1.20%5D", + "https://github.com/golang/go/issues/63417", + "https://go.dev/cl/534215", + "https://go.dev/cl/534235", + "https://go.dev/issue/63417", + "https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ", + "https://linux.oracle.com/cve/CVE-2023-39325.html", + "https://linux.oracle.com/errata/ELSA-2023-5867.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3OVW5V2DM5K5IC3H7O42YDUGNJ74J35O/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3SZN67IL7HMGMNAVLOTIXLIHUDXZK4LH/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WJ4QVX2AMUJ2F2S27POOAHRC4K3CHU4/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5RSKA2II6QTD4YUKUNDVJQSRYSFC4VFR/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVZDNSMVDAQJ64LJC5I5U5LDM5753647/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2BBIDR2ZMB3X5BC7SR4SLQMHRMVPY6L/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECRC75BQJP6FJN2L7KCKYZW4DSBD7QSD/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FTMJ3NJIDAZFWJQQSP3L22MUFJ3UP2PT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSY7SXFFTPZFWDM6XELSDSHZLVW3AHK7/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HZQIELEIRSZUYTFFH5KTH2YJ4IIQG2KE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPWCNYB5PQ5PCVZ4NJT6G56ZYFZ5QBU6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5E5JSJBZLYXOTZWXHJKRVCIXIHVWKJ6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZQYOOKHQDQ57LV2IAG6NRFOVXKHJJ3Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NG7IMPL55MVWU3LCI4JQJT3K2U5CHDV7/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ODBY7RVMGZCBSTWF2OZGIZS57FNFUL67/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXGWPQOJ3JNDW2XIYKIVJ7N7QUIFNM2Q/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PJCUNGIQDUMZ4Z6HWVYIMR66A35F5S74/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QF5QSYAOPDOWLY6DUHID56Q4HQFYB45I/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXOU2JZUBEBP7GBKAYIJRPRBZSJCD7ST/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3UETKPUB3V5JS5TLZOF3SMTGT5K5APS/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULQQONMSCQSH5Z5OWFFQHCGEZ3NL4DRJ/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTT7DG3QOF5ZNJLUGHDNLRUIN6OWZARP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2LZSWTV4NV4SNQARNXG5T6LRHP26EW2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WCNCBYKZXLDFGAJUB7ZP5VLC3YTHJNVH/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XTNLSL44Y5FB6JWADSZH6DCV4JJAAEQY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJWHBLVZDM5KQSDFRBFRKU5KSSOLIRQ4/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRKEXKANQ7BKJW2YTAMP625LJUJZLJ4P/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZSVEMQV5ROY5YW5QE3I57HT3ITWG5GCV/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-39325", + "https://pkg.go.dev/vuln/GO-2023-2102", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20231110-0008/", + "https://ubuntu.com/security/notices/USN-6574-1", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487", + "https://www.cve.org/CVERecord?id=CVE-2023-39325" + ], + "PublishedDate": "2023-10-11T22:15:09.88Z", + "LastModifiedDate": "2026-06-17T06:12:02.173Z" + }, + { + "VulnerabilityID": "CVE-2023-45283", + "VendorIDs": [ + "GO-2023-2185" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.11, 1.21.4, 1.20.12, 1.21.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c4ad514a551b012777568515c1515204853880960621cdceae41f410b24e1328", + "Title": "The filepath package does not recognize paths with a \\??\\ prefix as sp ...", + "Description": "The filepath package does not recognize paths with a \\??\\ prefix as special. On Windows, a path beginning with \\??\\ is a Root Local Device path equivalent to a path beginning with \\\\?\\. Paths with a \\??\\ prefix may be used to access arbitrary locations on the system. For example, the path \\??\\c:\\x is equivalent to the more common path c:\\x. Before fix, Clean could convert a rooted path such as \\a\\..\\??\\b into the root local device path \\??\\b. Clean will now convert this to .\\??\\b. Similarly, Join(\\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \\??\\b. Join will now convert this to \\.\\??\\b. In addition, with fix, IsAbs now correctly reports paths beginning with \\??\\ as absolute, and VolumeName correctly reports the \\??\\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \\?, resulting in filepath.Clean(\\?\\c:) returning \\?\\c: rather than \\?\\c:\\ (among other effects). The previous behavior has been restored.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "amazon": 2, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2023/12/05/2", + "https://go.dev/cl/540277", + "https://go.dev/cl/541175", + "https://go.dev/issue/63713", + "https://go.dev/issue/64028", + "https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY", + "https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45283", + "https://pkg.go.dev/vuln/GO-2023-2185", + "https://security.netapp.com/advisory/ntap-20231214-0008/" + ], + "PublishedDate": "2023-11-09T17:15:08.757Z", + "LastModifiedDate": "2026-06-17T06:28:34.863Z" + }, + { + "VulnerabilityID": "CVE-2023-45287", + "VendorIDs": [ + "GO-2023-2375" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45287", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3977cfb978ed1a535fa8a0d93d50e248d2e1513f61338355ae88e4918c323ba2", + "Title": "golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.", + "Description": "Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-203" + ], + "VendorSeverity": { + "alma": 2, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:2272", + "https://access.redhat.com/errata/RHSA-2024:2988", + "https://access.redhat.com/security/cve/CVE-2023-45287", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/2253330", + "https://bugzilla.redhat.com/show_bug.cgi?id=1983596", + "https://bugzilla.redhat.com/show_bug.cgi?id=1989575", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237773", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237776", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2244340", + "https://bugzilla.redhat.com/show_bug.cgi?id=2246840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2253330", + "https://bugzilla.redhat.com/show_bug.cgi?id=2254210", + "https://bugzilla.redhat.com/show_bug.cgi?id=2262272", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25091", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33198", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29409", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39318", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39319", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39326", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45287", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23650", + "https://errata.almalinux.org/9/ALSA-2024-2272.html", + "https://errata.rockylinux.org/RLSA-2024:2988", + "https://go.dev/cl/326012/26", + "https://go.dev/issue/20654", + "https://groups.google.com/g/golang-announce/c/QMK8IQALDvA", + "https://linux.oracle.com/cve/CVE-2023-45287.html", + "https://linux.oracle.com/errata/ELSA-2024-2988.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45287", + "https://people.redhat.com/~hkario/marvin/", + "https://pkg.go.dev/vuln/GO-2023-2375", + "https://security.netapp.com/advisory/ntap-20240112-0005/", + "https://www.cve.org/CVERecord?id=CVE-2023-45287" + ], + "PublishedDate": "2023-12-05T17:15:08.57Z", + "LastModifiedDate": "2026-06-17T06:28:35.46Z" + }, + { + "VulnerabilityID": "CVE-2023-45288", + "VendorIDs": [ + "GHSA-4v7x-pqxf-cx7m", + "GO-2024-2687" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.21.9, 1.22.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45288", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a75a8e0dac73914721893c558832ffdbd8d35944fe18a42195919a590e116d5f", + "Title": "golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS", + "Description": "An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "bottlerocket": 2, + "cbl-mariner": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288", + "http://www.openwall.com/lists/oss-security/2024/04/03/16", + "http://www.openwall.com/lists/oss-security/2024/04/05/4", + "https://access.redhat.com/errata/RHSA-2024:2724", + "https://access.redhat.com/security/cve/CVE-2023-45288", + "https://bugzilla.redhat.com/2268017", + "https://bugzilla.redhat.com/2268018", + "https://bugzilla.redhat.com/2268019", + "https://bugzilla.redhat.com/2268273", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268017", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268018", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268019", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268273", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45289", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45290", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24783", + "https://errata.almalinux.org/9/ALSA-2024-2724.html", + "https://errata.rockylinux.org/RLSA-2024:2724", + "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-c9wf-j9h6-m2r9", + "https://go.dev/cl/576155", + "https://go.dev/issue/65051", + "https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M", + "https://kb.cert.org/vuls/id/421644", + "https://linux.oracle.com/cve/CVE-2023-45288.html", + "https://linux.oracle.com/errata/ELSA-2024-3346.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRYFHIQ6XRKRYBI2F5UESH67BJBQXUPT/", + "https://nowotarski.info/http2-continuation-flood/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45288", + "https://pkg.go.dev/vuln/GO-2024-2687", + "https://security.netapp.com/advisory/ntap-20240419-0009/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2023-45288", + "https://www.kb.cert.org/vuls/id/421644" + ], + "PublishedDate": "2024-04-04T21:15:16.113Z", + "LastModifiedDate": "2026-06-17T06:28:35.58Z" + }, + { + "VulnerabilityID": "CVE-2024-34156", + "VendorIDs": [ + "GO-2024-3106" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.22.7, 1.23.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-34156", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0e3203160571cac9413517b97701f926f1a60af8405d0d8a6a813a1ec1484b4c", + "Title": "encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion", + "Description": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:3773", + "https://access.redhat.com/security/cve/CVE-2024-34156", + "https://bugzilla.redhat.com/2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341750", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341751", + "https://bugzilla.redhat.com/show_bug.cgi?id=2344219", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866", + "https://errata.almalinux.org/9/ALSA-2025-3773.html", + "https://errata.rockylinux.org/RLSA-2025:3773", + "https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01%20%28go1.22.7%29", + "https://github.com/golang/go/commit/fa8ff1a46deb6c816304441ec6740ec112e19012%20%28go1.23.1%29", + "https://go.dev/cl/611239", + "https://go.dev/issue/69139", + "https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc", + "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk", + "https://linux.oracle.com/cve/CVE-2024-34156.html", + "https://linux.oracle.com/errata/ELSA-2025-3773.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-34156", + "https://pkg.go.dev/vuln/GO-2024-3106", + "https://security.netapp.com/advisory/ntap-20240926-0004/", + "https://ubuntu.com/security/notices/USN-7081-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2024-34156" + ], + "PublishedDate": "2024-09-06T21:15:12.02Z", + "LastModifiedDate": "2026-06-17T07:33:00.72Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b9e31a7f7c23d6e7567894c6f5ef6157cfeaad544deb029b9d1fe3182da715dc", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-08-14T13:17:15.67Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d9d039a845d949dc8a74d8db4834ad2d5ca0569b6b2add1b1ea11a926c3f0fb9", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1ec1a7f89eb3c16440a940a26fa6e4fbfff38144f7c0755c93e5fe59cefa0d04", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-08-14T13:17:46.517Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a762e698bca7218956349d9f38dcfbc61c4868c7ab8ce3207ceca629f9c13a1b", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-08-14T13:17:49.537Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0d0ed0dd685268c2038aa98fa94aa9029958a1c032fa31ecd48b07862eb9d3c0", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-08-14T13:17:52.587Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:01658b116ae232cd7dcfbe251c759a3738c034a13808c31bd90f57738eaba52c", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3fdb391f8a8769dd94acdbd462773d300d2acd35190f1f9281d91af18976a60d", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-33722.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-08-14T13:17:54.66Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f82ab91def0bf153624a5b814761c99c6a1e43f03b80859f515691ec7a59cbe5", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:39319", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-39573.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-08-14T13:18:12Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b440ed57b07a3cce2065a857e7508a8c6d02438932b22fb1c3ea30afc5170113", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-08-13T13:18:25.52Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7849097aacfe4eb85b01b6f77d6e3fc9011aa302d0ef58941e9ff8e6b86cda0c", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-08-14T16:16:55.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c1fa9db4daaed24161ae596c784eb17b623a15b1c5772e4bfc502e63d909968a", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-08-14T13:18:23.657Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d522152771318b713fbe22e95bbab3beefa80be44845565b99b7bed857e7bb0c", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:37435", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-08-14T13:18:24.667Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:42567a6961dad05942c294980788301406043e33b2d5d7cfb1074a0ecb922b10", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:32f25fa4802288dd5d4fd7cc19a4144c80dbf6f5d31c8d3be0d8ada4763f3bbf", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d7a677267b726f8695ac57a03a921fe0126241be21bffbbd6ab97a7b21d9268b", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-08-14T13:18:47.497Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:fa4c728faebf6d82dd2523f7138485d8b9c00620f6b653b9ddec90f5ab2b403e", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e7bf8c06833aec6f8976dcaa2c9e3effc2244fce8b110067c231aeed5bbbb258", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-08-14T16:16:57.21Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:eb44897c56ee4d8c5ea8554b5e92dd3305f76b22305ccd644acf33ba41d0e473", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-08-14T16:16:57.367Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:33a25a8cde3519f84129a241b969bbbe732b4ab2b6d4c300c8abe05a112bb9a6", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-08-14T16:16:57.523Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3cb61d9eb801b0ec9c1ba6721bd516253c0fa7b4d37d3eb24e947a110c74dfa3", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-08-14T17:19:13.91Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "3f56a6ee72c00588" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:98bb5380f744473e59b3fa9b7956e49ccfb2fb9124efaca4e28a9f9c24acb91b", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-08-14T16:16:57.717Z" + }, + { + "VulnerabilityID": "CVE-2022-32149", + "VendorIDs": [ + "GHSA-69ch-w2m2-3vjp", + "GO-2022-1059" + ], + "PkgID": "golang.org/x/text@v0.3.7", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.3.7", + "UID": "39ab3982ac48cf2f" + }, + "InstalledVersion": "v0.3.7", + "FixedVersion": "0.3.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-32149", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9bbe211b2331ce9b3fe253b65e274ed5d7b1a3c3d518cd2895c7622a1b340a74", + "Title": "golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags", + "Description": "An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-772" + ], + "VendorSeverity": { + "azure": 3, + "cbl-mariner": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-32149", + "https://github.com/golang/text/commit/434eadcdbc3b0256971992e8c70027278364c72c%20%28v0.3.8%29", + "https://go.dev/cl/442235", + "https://go.dev/issue/56152", + "https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ", + "https://groups.google.com/g/golang-dev/c/qfPIly0X7aU", + "https://nvd.nist.gov/vuln/detail/CVE-2022-32149", + "https://pkg.go.dev/vuln/GO-2022-1059", + "https://security.netapp.com/advisory/ntap-20230203-0006/", + "https://ubuntu.com/security/notices/USN-5873-1", + "https://www.cve.org/CVERecord?id=CVE-2022-32149" + ], + "PublishedDate": "2022-10-14T15:15:34.543Z", + "LastModifiedDate": "2026-06-17T04:46:45.967Z" + }, + { + "VulnerabilityID": "CVE-2026-56852", + "VendorIDs": [ + "GO-2026-5970" + ], + "PkgID": "golang.org/x/text@v0.3.7", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.3.7", + "UID": "39ab3982ac48cf2f" + }, + "InstalledVersion": "v0.3.7", + "FixedVersion": "0.39.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56852", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:05748972227e2ae3fd4c23699b9515d2b307f662c7475f1c48953d8a1e3188f8", + "Title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input", + "Description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56852", + "https://go.dev/cl/794100", + "https://go.dev/issue/80142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56852", + "https://pkg.go.dev/vuln/GO-2026-5970", + "https://www.cve.org/CVERecord?id=CVE-2026-56852" + ], + "PublishedDate": "2026-07-21T20:17:02.867Z", + "LastModifiedDate": "2026-07-23T18:27:48.877Z" + }, + { + "VulnerabilityID": "CVE-2022-23806", + "VendorIDs": [ + "GO-2021-0319" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.14, 1.17.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23806", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9b33440128e5d35602d9eb4b487756c84de4457d2766caafb061b604ea23b40f", + "Title": "golang: crypto/elliptic: IsOnCurve returns true for invalid field elements", + "Description": "Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-252" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V3Score": 9.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V2Score": 6.4, + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2022-23806", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/382455", + "https://go.dev/issue/50974", + "https://go.googlesource.com/go/+/7f9494c277a471f6f47f4af3036285c0b1419816", + "https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ", + "https://linux.oracle.com/cve/CVE-2022-23806.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23806", + "https://pkg.go.dev/vuln/GO-2021-0319", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220225-0006/", + "https://www.cve.org/CVERecord?id=CVE-2022-23806", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-02-11T01:15:07.747Z", + "LastModifiedDate": "2026-06-17T04:30:48.69Z" + }, + { + "VulnerabilityID": "CVE-2023-24538", + "VendorIDs": [ + "GO-2023-1703" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24538", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2c7e9d87adc6db76b6384dae60a4523b75f1c1fcc25d12dd8aa33e9e6b1d38f0", + "Title": "golang: html/template: backticks not treated as string delimiters", + "Description": "Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. \"var a = {{.}}\"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24538", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/20374d1d759bc4e17486bde1cb9dca5be37d9e52%20%28go1.20.3%29", + "https://github.com/golang/go/commit/b1e3ecfa06b67014429a197ec5e134ce4303ad9b%20%28go1.19.8%29", + "https://github.com/golang/go/issues/59234", + "https://go.dev/cl/482079", + "https://go.dev/issue/59234", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24538.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24538", + "https://pkg.go.dev/vuln/GO-2023-1703", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241115-0007/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24538" + ], + "PublishedDate": "2023-04-06T16:15:07.8Z", + "LastModifiedDate": "2026-06-17T05:39:29.67Z" + }, + { + "VulnerabilityID": "CVE-2023-24540", + "VendorIDs": [ + "GO-2023-1752" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24540", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:235afad998e4b2314abdc8304a2f84cc571dd858f596571825b2e6e57640c793", + "Title": "golang: html/template: improper handling of JavaScript whitespace", + "Description": "Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set \"\\t\\n\\f\\r\\u0020\\u2028\\u2029\" in JavaScript contexts that also contain actions may not be properly sanitized during execution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-77" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24540", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/4a28cad66655ee01c6e944271e23c33cab021765%20%28go1.20.4%29", + "https://github.com/golang/go/commit/ce7bd33345416e6d8cac901792060591cafc2797%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59721", + "https://go.dev/cl/491616", + "https://go.dev/issue/59721", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-24540.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24540", + "https://pkg.go.dev/vuln/GO-2023-1752", + "https://security.netapp.com/advisory/ntap-20241115-0008/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24540" + ], + "PublishedDate": "2023-05-11T16:15:09.687Z", + "LastModifiedDate": "2026-06-17T05:39:30.007Z" + }, + { + "VulnerabilityID": "CVE-2024-24790", + "VendorIDs": [ + "GO-2024-2887" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.21.11, 1.22.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-24790", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e69a2b8bf02bfe571a18755ad8064aa2d7f67d9a22d8f1bf778fdd1965445bd9", + "Title": "golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses", + "Description": "The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.", + "Severity": "CRITICAL", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "bottlerocket": 2, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.7 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "http://www.openwall.com/lists/oss-security/2024/06/04/1", + "https://access.redhat.com/errata/RHSA-2025:7256", + "https://access.redhat.com/security/cve/CVE-2024-24790", + "https://bugzilla.redhat.com/2237777", + "https://bugzilla.redhat.com/2237778", + "https://bugzilla.redhat.com/2279814", + "https://bugzilla.redhat.com/2292787", + "https://bugzilla.redhat.com/2295310", + "https://bugzilla.redhat.com/2315719", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2279814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2292787", + "https://bugzilla.redhat.com/show_bug.cgi?id=2295310", + "https://bugzilla.redhat.com/show_bug.cgi?id=2315719", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24788", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24791", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9355", + "https://errata.almalinux.org/9/ALSA-2025-7256.html", + "https://errata.rockylinux.org/RLSA-2025:7256", + "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/2.9.0/BRSA-glvb5gspjgq6.toml", + "https://github.com/golang/go/commit/051bdf3fd12a40307606ff9381138039c5f452f0%20%281.21%29", + "https://github.com/golang/go/commit/12d5810cdb1f73cf23d7a86462143e9463317fca%20%281.22%29", + "https://github.com/golang/go/issues/67680", + "https://go.dev/cl/590316", + "https://go.dev/issue/67680", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ", + "https://linux.oracle.com/cve/CVE-2024-24790.html", + "https://linux.oracle.com/errata/ELSA-2025-7256.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-24790", + "https://pkg.go.dev/vuln/GO-2024-2887", + "https://security.netapp.com/advisory/ntap-20240905-0002/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2024-24790" + ], + "PublishedDate": "2024-06-05T16:15:10.56Z", + "LastModifiedDate": "2026-06-17T07:14:52.097Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e0e19c71d9da1356bafdb791806ad20617b3b4ff98c63a66848cfd42092d91ae", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2021-39293", + "VendorIDs": [ + "GO-2022-0273" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.8, 1.17.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-39293", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6efc60f9da88f683e525e5a79de9c9b7a04c73bada1f593e7760cd7c0b97f4b2", + "Title": "golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196)", + "Description": "In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-39293", + "https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/343434", + "https://go.dev/issue/47801", + "https://go.googlesource.com/go/+/bacbc33439b124ffd7392c91a5f5d96eca8c0c0b", + "https://groups.google.com/g/golang-announce/c/dx9d7IOseHw", + "https://linux.oracle.com/cve/CVE-2021-39293.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-39293", + "https://pkg.go.dev/vuln/GO-2022-0273", + "https://security.netapp.com/advisory/ntap-20220217-0009/", + "https://www.cve.org/CVERecord?id=CVE-2021-39293" + ], + "PublishedDate": "2022-01-24T01:15:07.92Z", + "LastModifiedDate": "2026-06-17T04:03:28.747Z" + }, + { + "VulnerabilityID": "CVE-2021-41771", + "VendorIDs": [ + "GO-2021-0263" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.10, 1.17.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-41771", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:42e8ab3cb6ffbe559128c65406be50fce3f4799b8b9b2ad4b4b73a8f619ad7de", + "Title": "golang: debug/macho: invalid dynamic symbol table command can cause panic", + "Description": "ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-119" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-41771", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/367075", + "https://go.dev/issue/48990", + "https://go.googlesource.com/go/+/61536ec03063b4951163bd09609c86d82631fa27", + "https://groups.google.com/g/golang-announce/c/0fM21h43arc", + "https://linux.oracle.com/cve/CVE-2021-41771.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4OFS3M3OFB24SWPTIAPARKGPUMQVUY6Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ON7BQRRJZBOR5TJHURBAB3WLF4YXFC6Z/", + "https://nvd.nist.gov/vuln/detail/CVE-2021-41771", + "https://pkg.go.dev/vuln/GO-2021-0263", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20211210-0003/", + "https://www.cve.org/CVERecord?id=CVE-2021-41771", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-11-08T06:15:08.057Z", + "LastModifiedDate": "2026-06-17T04:08:53.673Z" + }, + { + "VulnerabilityID": "CVE-2021-41772", + "VendorIDs": [ + "GO-2021-0264" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.10, 1.17.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-41772", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:382e1185737253da69a783b9499c90f5f113a71faf44bd84d7607572a31bfbee", + "Title": "golang: archive/zip: Reader.Open panics on empty string", + "Description": "Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-41772", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/349770", + "https://go.dev/issue/48085", + "https://go.googlesource.com/go/+/b24687394b55a93449e2be4e6892ead58ea9a10f", + "https://groups.google.com/g/golang-announce/c/0fM21h43arc", + "https://linux.oracle.com/cve/CVE-2021-41772.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4OFS3M3OFB24SWPTIAPARKGPUMQVUY6Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ON7BQRRJZBOR5TJHURBAB3WLF4YXFC6Z/", + "https://nvd.nist.gov/vuln/detail/CVE-2021-41772", + "https://pkg.go.dev/vuln/GO-2021-0264", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20211210-0003/", + "https://www.cve.org/CVERecord?id=CVE-2021-41772", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-11-08T06:15:08.107Z", + "LastModifiedDate": "2026-06-17T04:08:53.8Z" + }, + { + "VulnerabilityID": "CVE-2021-44716", + "VendorIDs": [ + "GHSA-vc3p-29h2-gpcp", + "GO-2022-0288" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.12, 1.17.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-44716", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:09580866673667aa63a60b4e1653f81745c1c66d442fc266d06a63551c13fb5e", + "Title": "golang: net/http: limit growth of header canonicalization cache", + "Description": "net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:0001", + "https://access.redhat.com/security/cve/CVE-2021-44716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2030801", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44716", + "https://errata.rockylinux.org/RLSA-2022:0001", + "https://github.com/golang/go/commit/48d948963c5ce7add72af5665a871caff6c1d35a%20%28go1.17.5%29", + "https://github.com/golang/net/commit/491a49abca63de5e07ef554052d180a1b5fe2d70", + "https://go.dev/cl/369794", + "https://go.dev/issue/50058", + "https://groups.google.com/g/golang-announce/c/hcmEScgc00k", + "https://groups.google.com/g/golang-announce/c/hcmEScgc00k/m/ZWnOjeY4CQAJ", + "https://linux.oracle.com/cve/CVE-2021-44716.html", + "https://linux.oracle.com/errata/ELSA-2022-0001.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-44716", + "https://pkg.go.dev/vuln/GO-2022-0288", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220121-0002/", + "https://www.cve.org/CVERecord?id=CVE-2021-44716" + ], + "PublishedDate": "2022-01-01T05:15:08.307Z", + "LastModifiedDate": "2026-06-17T04:12:45.48Z" + }, + { + "VulnerabilityID": "CVE-2022-23772", + "VendorIDs": [ + "GO-2021-0317" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.14, 1.17.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23772", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4a74a69dc58f8fea47672f8491856dad40c8dde22811bf7d603ef5baf8664ca3", + "Title": "golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString", + "Description": "Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:C", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 7.8, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2022-23772", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/379537", + "https://go.dev/issue/50699", + "https://go.googlesource.com/go/+/ad345c265916bbf6c646865e4642eafce6d39e78", + "https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ", + "https://linux.oracle.com/cve/CVE-2022-23772.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23772", + "https://pkg.go.dev/vuln/GO-2021-0317", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220225-0006/", + "https://www.cve.org/CVERecord?id=CVE-2022-23772", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-02-11T01:15:07.657Z", + "LastModifiedDate": "2026-06-17T04:30:46.407Z" + }, + { + "VulnerabilityID": "CVE-2022-24675", + "VendorIDs": [ + "GO-2022-0433" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.9, 1.18.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-24675", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:16302719991b22ba6ac494e507681c54f6bc325560af1950db06b93551b0eb6b", + "Title": "golang: encoding/pem: fix stack overflow in Decode", + "Description": "encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-24675", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/399820", + "https://go.dev/issue/51853", + "https://go.googlesource.com/go/+/45c3387d777caf28f4b992ad9a6216e3085bb8fe", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/oecdBNLOml8", + "https://linux.oracle.com/cve/CVE-2022-24675.html", + "https://linux.oracle.com/errata/ELSA-2022-5337.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TYZC4OAY54TO75FBEFAPV5G7O4D5TM/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F3BMW5QGX53CMIJIZWKXFKBJX2C5GWTY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RCRSABD6CUDIZULZPZL5BJ3ET3A2NEJP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-24675", + "https://pkg.go.dev/vuln/GO-2022-0433", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220915-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-24675" + ], + "PublishedDate": "2022-04-20T10:15:07.93Z", + "LastModifiedDate": "2026-06-17T04:32:16.51Z" + }, + { + "VulnerabilityID": "CVE-2022-24921", + "VendorIDs": [ + "GO-2021-0347" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.15, 1.17.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-24921", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:553f2b0b05dc25b01613dde935d9d9c8233c5edf8f1c552eb8008f39b07363fc", + "Title": "golang: regexp: stack exhaustion via a deeply nested expression", + "Description": "regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-24921", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/384616", + "https://go.dev/issue/51112", + "https://go.googlesource.com/go/+/452f24ae94f38afa3704d4361d91d51218405c0a", + "https://groups.google.com/g/golang-announce/c/RP1hfrBYVuk", + "https://linux.oracle.com/cve/CVE-2022-24921.html", + "https://linux.oracle.com/errata/ELSA-2022-9363.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-24921", + "https://pkg.go.dev/vuln/GO-2021-0347", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220325-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-24921" + ], + "PublishedDate": "2022-03-05T20:15:08.323Z", + "LastModifiedDate": "2026-06-17T04:32:47.957Z" + }, + { + "VulnerabilityID": "CVE-2022-27664", + "VendorIDs": [ + "GHSA-69cg-p879-7622", + "GO-2022-0969" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.6, 1.19.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-27664", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:faa663b3f43ad1245d08cd9290ee0c56203f3c49d4f7fc924e6421a2f44048e3", + "Title": "golang: net/http: handle server errors after sending GOAWAY", + "Description": "In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:2177", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-27664", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2124669", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27664", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2023:2177", + "https://github.com/golang/go/commit/5bc9106458fc07851ac324a4157132a91b1f3479%20%28go1.18.6%29", + "https://github.com/golang/go/commit/9cfe4e258b1c9d4a04a42539c21c7bdb2e227824%20%28go1.19.1%29", + "https://github.com/golang/go/issues/54658", + "https://go.dev/cl/428735", + "https://go.dev/issue/54658", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s", + "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s/m/0tgO0pjiBQAJ", + "https://linux.oracle.com/cve/CVE-2022-27664.html", + "https://linux.oracle.com/errata/ELSA-2024-0121.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-27664", + "https://pkg.go.dev/vuln/GO-2022-0969", + "https://security.gentoo.org/glsa/202209-26", + "https://security.netapp.com/advisory/ntap-20220923-0004/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-8089-1", + "https://ubuntu.com/security/notices/USN-8089-2", + "https://ubuntu.com/security/notices/USN-8089-3", + "https://www.cve.org/CVERecord?id=CVE-2022-27664" + ], + "PublishedDate": "2022-09-06T18:15:12.747Z", + "LastModifiedDate": "2026-06-17T04:37:26.873Z" + }, + { + "VulnerabilityID": "CVE-2022-28131", + "VendorIDs": [ + "GO-2022-0521" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-28131", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b92652e50fdd77d82c73b4a5e5bf897a18fd90080aadd76940cbc9ca1c3e06d2", + "Title": "golang: encoding/xml: stack exhaustion in Decoder.Skip", + "Description": "Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8057", + "https://access.redhat.com/security/cve/CVE-2022-28131", + "https://bugzilla.redhat.com/2044628", + "https://bugzilla.redhat.com/2045880", + "https://bugzilla.redhat.com/2050648", + "https://bugzilla.redhat.com/2050742", + "https://bugzilla.redhat.com/2050743", + "https://bugzilla.redhat.com/2065290", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107376", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2107390", + "https://bugzilla.redhat.com/2107392", + "https://bugzilla.redhat.com/show_bug.cgi?id=2044628", + "https://bugzilla.redhat.com/show_bug.cgi?id=2045880", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050648", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050742", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2055349", + "https://bugzilla.redhat.com/show_bug.cgi?id=2065290", + "https://bugzilla.redhat.com/show_bug.cgi?id=2104367", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23648", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21698", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21702", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21713", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2022-8057.html", + "https://errata.rockylinux.org/RLSA-2022:8057", + "https://github.com/golang/go/commit/90f040ec510dd678b7860d70ca77e5682f4c7e96", + "https://go.dev/cl/417062", + "https://go.dev/issue/53614", + "https://go.googlesource.com/go/+/08c46ed43d80bbb67cb904944ea3417989be4af3", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-28131.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-28131", + "https://pkg.go.dev/vuln/GO-2022-0521", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-28131" + ], + "PublishedDate": "2022-08-10T20:15:32.767Z", + "LastModifiedDate": "2026-06-17T04:38:02.23Z" + }, + { + "VulnerabilityID": "CVE-2022-28327", + "VendorIDs": [ + "GO-2022-0435" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.9, 1.18.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-28327", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3e050a4598e895ee12c4be3c3f71b2ceaefdba3db44b355f8c9274c4a058e678", + "Title": "golang: crypto/elliptic: panic caused by oversized scalar", + "Description": "The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-28327", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/397135", + "https://go.dev/issue/52075", + "https://go.googlesource.com/go/+/37065847d87df92b5eb246c88ba2085efcf0b331", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/oecdBNLOml8", + "https://linux.oracle.com/cve/CVE-2022-28327.html", + "https://linux.oracle.com/errata/ELSA-2022-5337.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TYZC4OAY54TO75FBEFAPV5G7O4D5TM/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F3BMW5QGX53CMIJIZWKXFKBJX2C5GWTY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NY6GEAJMNKKMU5H46QO4D7D6A24KSPXE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RCRSABD6CUDIZULZPZL5BJ3ET3A2NEJP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-28327", + "https://pkg.go.dev/vuln/GO-2022-0435", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220915-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-28327" + ], + "PublishedDate": "2022-04-20T10:15:08.03Z", + "LastModifiedDate": "2026-06-17T04:38:23.653Z" + }, + { + "VulnerabilityID": "CVE-2022-2879", + "VendorIDs": [ + "GO-2022-1037" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-2879", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:82a6c50331e36d85b72e596efd46be55fb1a76875ad8877e019bee3adda86078", + "Title": "golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers", + "Description": "Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2204", + "https://access.redhat.com/security/cve/CVE-2022-2879", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132867", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2204.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/0a723816cd205576945fa57fbdde7e6532d59d08%20%28go1.18.7%29", + "https://github.com/golang/go/commit/4fa773cdefd20be093c84f731be7d4febf5536fa%20%28go1.19.2%29", + "https://github.com/golang/go/issues/54853", + "https://github.com/vbatts/tar-split/releases/tag/v0.12.1", + "https://go.dev/cl/439355", + "https://go.dev/issue/54853", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-2879.html", + "https://linux.oracle.com/errata/ELSA-2024-2988.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-2879", + "https://pkg.go.dev/vuln/GO-2022-1037", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-2879" + ], + "PublishedDate": "2022-10-14T15:15:17.647Z", + "LastModifiedDate": "2026-06-17T04:42:45.443Z" + }, + { + "VulnerabilityID": "CVE-2022-2880", + "VendorIDs": [ + "GO-2022-1038" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-2880", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f3cf22900230b0e0556e31c95afebf9bf8149220710c84129e38f8c8e865a0f8", + "Title": "golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters", + "Description": "Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-444" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-2880", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/9d2c73a9fd69e45876509bb3bdb2af99bf77da1e%20%28go1.18.7%29", + "https://github.com/golang/go/commit/f6d844510d5f1e3b3098eba255d9b633d45eac3b%20%28go1.19.2%29", + "https://github.com/golang/go/issues/54663", + "https://go.dev/cl/432976", + "https://go.dev/issue/54663", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-2880.html", + "https://linux.oracle.com/errata/ELSA-2024-3254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-2880", + "https://pkg.go.dev/vuln/GO-2022-1038", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-2880" + ], + "PublishedDate": "2022-10-14T15:15:18.09Z", + "LastModifiedDate": "2026-06-17T04:42:45.547Z" + }, + { + "VulnerabilityID": "CVE-2022-29804", + "VendorIDs": [ + "GO-2022-0533" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-29804", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c5fd9928912613b0f4d6405329c69943580a5a29f3cfcc0d2fa56f2bd20677b0", + "Title": "ELSA-2022-17957: ol8addon security update (IMPORTANT)", + "Description": "Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/401595", + "https://go.dev/issue/52476", + "https://go.googlesource.com/go/+/9cd1818a7d019c02fa4898b3e45a323e35033290", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-29804.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-29804", + "https://pkg.go.dev/vuln/GO-2022-0533" + ], + "PublishedDate": "2022-08-10T20:15:34.89Z", + "LastModifiedDate": "2026-06-17T04:40:44.503Z" + }, + { + "VulnerabilityID": "CVE-2022-30580", + "VendorIDs": [ + "GO-2022-0532" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30580", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c2edbb0b0b8c985f7d4c578cad87f00aff62e647a60f22d2723d3ce9c572de22", + "Title": "golang: os/exec: Code injection in Cmd.Start", + "Description": "Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either \"..com\" or \"..exe\" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-30580", + "https://go.dev/cl/403759", + "https://go.dev/issue/52574", + "https://go.googlesource.com/go/+/960ffa98ce73ef2c2060c84c7ac28d37a83f345e", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-30580.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30580", + "https://pkg.go.dev/vuln/GO-2022-0532", + "https://www.cve.org/CVERecord?id=CVE-2022-30580" + ], + "PublishedDate": "2022-08-10T20:15:40.227Z", + "LastModifiedDate": "2026-06-17T04:43:53.69Z" + }, + { + "VulnerabilityID": "CVE-2022-30630", + "VendorIDs": [ + "GO-2022-0527" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30630", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:26a577922c8f6d2b3e9f14a94e505da5ec3a280cbde471a8b83b37d8b07eaa8f", + "Title": "golang: io/fs: stack exhaustion in Glob", + "Description": "Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30630", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/315e80d293b684ac2902819e58f618f1b5a14d49%20%281.18%29", + "https://go.dev/cl/417065", + "https://go.dev/issue/53415", + "https://go.googlesource.com/go/+/fa2d41d0ca736f3ad6b200b2a4e134364e9acc59", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30630.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30630", + "https://pkg.go.dev/vuln/GO-2022-0527", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30630" + ], + "PublishedDate": "2022-08-10T20:15:40.977Z", + "LastModifiedDate": "2026-06-17T04:43:58.727Z" + }, + { + "VulnerabilityID": "CVE-2022-30631", + "VendorIDs": [ + "GO-2022-0524" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30631", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8245055881b988f46898bece7028857f4a848e3a0c66fbfb1336500063819a38", + "Title": "golang: compress/gzip: stack exhaustion in Reader.Read", + "Description": "Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30631", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/8e27a8ac4c001c27713810b75925aa3794049c48%20%281.18%29", + "https://go.dev/cl/417067", + "https://go.dev/issue/53168", + "https://go.googlesource.com/go/+/b2b8872c876201eac2d0707276c6999ff3eb185e", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30631.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30631", + "https://pkg.go.dev/vuln/GO-2022-0524", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30631" + ], + "PublishedDate": "2022-08-10T20:15:41.373Z", + "LastModifiedDate": "2026-06-17T04:43:58.893Z" + }, + { + "VulnerabilityID": "CVE-2022-30632", + "VendorIDs": [ + "GO-2022-0522" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30632", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:80c30de1b4a71b6ce9b3c761aadd00b8f5a41581d9473dbb15544b33e7b02c2e", + "Title": "golang: path/filepath: stack exhaustion in Glob", + "Description": "Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30632", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/5ebd862b1714dad1544bd10a24c47cdb53ad7f46%20%281.18%29", + "https://go.dev/cl/417066", + "https://go.dev/issue/53416", + "https://go.googlesource.com/go/+/ac68c6c683409f98250d34ad282b9e1b0c9095ef", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30632.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30632", + "https://pkg.go.dev/vuln/GO-2022-0522", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30632" + ], + "PublishedDate": "2022-08-10T20:15:41.877Z", + "LastModifiedDate": "2026-06-17T04:43:59.057Z" + }, + { + "VulnerabilityID": "CVE-2022-30633", + "VendorIDs": [ + "GO-2022-0523" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30633", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d9b6d8d0951aa6294737684e5c1c93c1b1bdc39f13fcff915b39a247dcf46319", + "Title": "golang: encoding/xml: stack exhaustion in Unmarshal", + "Description": "Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8057", + "https://access.redhat.com/security/cve/CVE-2022-30633", + "https://bugzilla.redhat.com/2044628", + "https://bugzilla.redhat.com/2045880", + "https://bugzilla.redhat.com/2050648", + "https://bugzilla.redhat.com/2050742", + "https://bugzilla.redhat.com/2050743", + "https://bugzilla.redhat.com/2065290", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107376", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2107390", + "https://bugzilla.redhat.com/2107392", + "https://bugzilla.redhat.com/show_bug.cgi?id=2044628", + "https://bugzilla.redhat.com/show_bug.cgi?id=2045880", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050648", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050742", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2055349", + "https://bugzilla.redhat.com/show_bug.cgi?id=2065290", + "https://bugzilla.redhat.com/show_bug.cgi?id=2104367", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23648", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21698", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21702", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21713", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2022-8057.html", + "https://errata.rockylinux.org/RLSA-2022:8057", + "https://github.com/golang/go/commit/2924ced71d16297320e8ff18829c2038e6ad8d9b%20%281.18%29", + "https://go.dev/cl/417061", + "https://go.dev/issue/53611", + "https://go.googlesource.com/go/+/c4c1993fd2a5b26fe45c09592af6d3388a3b2e08", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30633.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30633", + "https://pkg.go.dev/vuln/GO-2022-0523", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30633" + ], + "PublishedDate": "2022-08-10T20:15:42.21Z", + "LastModifiedDate": "2026-06-17T04:43:59.163Z" + }, + { + "VulnerabilityID": "CVE-2022-30634", + "VendorIDs": [ + "GO-2022-0477" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30634", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:edd9b45050d676a25ba89796956ca9083019b2e81f63fa64556036861fd65dfe", + "Title": "ELSA-2022-17957: ol8addon security update (IMPORTANT)", + "Description": "Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/402257", + "https://go.dev/issue/52561", + "https://go.googlesource.com/go/+/bb1f4416180511231de6d17a1f2f55c82aafc863", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-30634.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30634", + "https://pkg.go.dev/vuln/GO-2022-0477" + ], + "PublishedDate": "2022-07-15T20:15:08.597Z", + "LastModifiedDate": "2026-06-17T04:43:59.317Z" + }, + { + "VulnerabilityID": "CVE-2022-30635", + "VendorIDs": [ + "GO-2022-0526" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30635", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:cdbe1bd007470a2a24718b0910bea73774c8a6704c174cc5c0f0d5ec558a5241", + "Title": "golang: encoding/gob: stack exhaustion in Decoder.Decode", + "Description": "Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-30635", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/fb979a50823e5a0575cf6166b3f17a13364cbf81%20%281.18%29", + "https://go.dev/cl/417064", + "https://go.dev/issue/53615", + "https://go.googlesource.com/go/+/6fa37e98ea4382bf881428ee0c150ce591500eb7", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30635.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30635", + "https://pkg.go.dev/vuln/GO-2022-0526", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30635" + ], + "PublishedDate": "2022-08-10T20:15:42.64Z", + "LastModifiedDate": "2026-06-17T04:43:59.43Z" + }, + { + "VulnerabilityID": "CVE-2022-32189", + "VendorIDs": [ + "GO-2022-0537" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.13, 1.18.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-32189", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:041405877467e09970e82a8675d702fbb9cf49853ff57eb95d3fe4cb90d420bd", + "Title": "golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service", + "Description": "A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 1, + "rocky": 1, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:7950", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-32189", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2059869", + "https://bugzilla.redhat.com/show_bug.cgi?id=2059870", + "https://bugzilla.redhat.com/show_bug.cgi?id=2060061", + "https://bugzilla.redhat.com/show_bug.cgi?id=2062597", + "https://bugzilla.redhat.com/show_bug.cgi?id=2064087", + "https://bugzilla.redhat.com/show_bug.cgi?id=2088459", + "https://bugzilla.redhat.com/show_bug.cgi?id=2105961", + "https://bugzilla.redhat.com/show_bug.cgi?id=2110864", + "https://bugzilla.redhat.com/show_bug.cgi?id=2113814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2118831", + "https://bugzilla.redhat.com/show_bug.cgi?id=2123055", + "https://bugzilla.redhat.com/show_bug.cgi?id=2123210", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32189", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2022:7950", + "https://github.com/golang/go/commit/9240558e4f342fc6e98fec22de17c04b45089349%20%281.18%29", + "https://go.dev/cl/417774", + "https://go.dev/issue/53871", + "https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66", + "https://groups.google.com/g/golang-announce/c/YqYYG87xB10", + "https://groups.google.com/g/golang-nuts/c/DCFSyTGM0wU", + "https://linux.oracle.com/cve/CVE-2022-32189.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-32189", + "https://pkg.go.dev/vuln/GO-2022-0537", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-32189" + ], + "PublishedDate": "2022-08-10T20:15:47.507Z", + "LastModifiedDate": "2026-06-17T04:46:49.81Z" + }, + { + "VulnerabilityID": "CVE-2022-41715", + "VendorIDs": [ + "GO-2022-1039" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41715", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a7e4e370d5845127d6bed035457b9a1f50588ebea70b8d5a2a54741653d805b8", + "Title": "golang: regexp/syntax: limit memory used by parsing regexps", + "Description": "Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2592", + "https://access.redhat.com/security/cve/CVE-2022-41715", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2592.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/645abfe529dc325e16daa17210640c2907d1c17a%20%28go1.19.2%29", + "https://github.com/golang/go/commit/e9017c2416ad0ef642f5e0c2eab2dbf3cba4d997%20%28go1.18.7%29", + "https://github.com/golang/go/issues/55949", + "https://go.dev/cl/439356", + "https://go.dev/issue/55949", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-41715.html", + "https://linux.oracle.com/errata/ELSA-2024-3254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41715", + "https://pkg.go.dev/vuln/GO-2022-1039", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41715" + ], + "PublishedDate": "2022-10-14T15:16:20.78Z", + "LastModifiedDate": "2026-06-17T05:03:41.893Z" + }, + { + "VulnerabilityID": "CVE-2022-41716", + "VendorIDs": [ + "GO-2022-1095" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.8, 1.19.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41716", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:47c066164946bf6931db7dbacc0a6d85e684fbf35cff861927b1bd07f71fd305", + "Title": "Due to unsanitized NUL values, attackers may be able to maliciously se ...", + "Description": "Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string \"A=B\\x00C=D\" sets the variables \"A=B\" and \"C=D\".", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/446916", + "https://go.dev/issue/56284", + "https://groups.google.com/g/golang-announce/c/mbHY1UY3BaM/m/hSpmRzk-AgAJ", + "https://linux.oracle.com/cve/CVE-2022-41716.html", + "https://linux.oracle.com/errata/ELSA-2023-18908.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41716", + "https://pkg.go.dev/vuln/GO-2022-1095", + "https://security.netapp.com/advisory/ntap-20230120-0007/" + ], + "PublishedDate": "2022-11-02T16:15:11.15Z", + "LastModifiedDate": "2026-06-17T05:03:41.997Z" + }, + { + "VulnerabilityID": "CVE-2022-41720", + "VendorIDs": [ + "GO-2022-1143" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.9, 1.19.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41720", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5691e032ce19970fe4cd4a4e1cee8ebe2cb8916e52ef435620ea331dd10fa88f", + "Title": "golang: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows", + "Description": "On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS(\"C:/tmp\").Open(\"COM1\") opens the COM1 device. Both os.DirFS and http.Dir only provide read-only filesystem access. In addition, on Windows, an os.DirFS for the directory (the root of the current drive) can permit a maliciously crafted path to escape from the drive and access any path on the system. With fix applied, the behavior of os.DirFS(\"\") has changed. Previously, an empty root was treated equivalently to \"/\", so os.DirFS(\"\").Open(\"tmp\") would open the path \"/tmp\". This now returns an error.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-41720", + "https://go.dev/cl/455716", + "https://go.dev/issue/56694", + "https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ", + "https://linux.oracle.com/cve/CVE-2022-41720.html", + "https://linux.oracle.com/errata/ELSA-2023-18908.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41720", + "https://pkg.go.dev/vuln/GO-2022-1143", + "https://www.cve.org/CVERecord?id=CVE-2022-41720" + ], + "PublishedDate": "2022-12-07T17:15:10.293Z", + "LastModifiedDate": "2026-06-17T05:03:42.497Z" + }, + { + "VulnerabilityID": "CVE-2022-41722", + "VendorIDs": [ + "GO-2023-1568" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41722", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:65dbb8433a5158c6bfd6aa41a603dc4331c5642fb72d3d685b450c98600c589f", + "Title": "golang: path/filepath: path-filepath filepath.Clean path traversal", + "Description": "A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as \"a/../c:/b\" into the valid path \"c:\\b\". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path \".\\c:\\b\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-41722", + "https://go.dev/cl/468123", + "https://go.dev/issue/57274", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41722", + "https://pkg.go.dev/vuln/GO-2023-1568", + "https://www.cve.org/CVERecord?id=CVE-2022-41722" + ], + "PublishedDate": "2023-02-28T18:15:09.887Z", + "LastModifiedDate": "2026-06-17T05:03:42.79Z" + }, + { + "VulnerabilityID": "CVE-2022-41723", + "VendorIDs": [ + "GHSA-vvpx-j8f3-3w6h", + "GO-2023-1571" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41723", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e270ba944c1674e85b909776583b23f54b929ccf65042fe293a954d98ba3a28c", + "Title": "golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding", + "Description": "A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41723", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/advisories/GHSA-vvpx-j8f3-3w6h", + "https://go.dev/cl/468135", + "https://go.dev/cl/468295", + "https://go.dev/issue/57855", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41723.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MA5XS5DAOJ5PKKNG5TUXKPQOFHT5VBC/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGW7GE2Z32ZT47UFAQFDRQE33B7Q7LMT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41723", + "https://pkg.go.dev/vuln/GO-2023-1571", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230331-0010/", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://ubuntu.com/security/notices/USN-8089-1", + "https://ubuntu.com/security/notices/USN-8089-2", + "https://ubuntu.com/security/notices/USN-8089-3", + "https://vuln.go.dev/ID/GO-2023-1571.json", + "https://www.couchbase.com/alerts/", + "https://www.cve.org/CVERecord?id=CVE-2022-41723" + ], + "PublishedDate": "2023-02-28T18:15:09.98Z", + "LastModifiedDate": "2026-06-17T05:03:42.9Z" + }, + { + "VulnerabilityID": "CVE-2022-41724", + "VendorIDs": [ + "GO-2023-1570" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41724", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:62c2130e0866c7e88a00767b6753ceb60229086cd95e11e66f6d4a18935d7743", + "Title": "golang: crypto/tls: large handshake records may cause panics", + "Description": "Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41724", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://go.dev/cl/468125", + "https://go.dev/issue/58001", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41724.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41724", + "https://pkg.go.dev/vuln/GO-2023-1570", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41724" + ], + "PublishedDate": "2023-02-28T18:15:10.043Z", + "LastModifiedDate": "2026-06-17T05:03:43.11Z" + }, + { + "VulnerabilityID": "CVE-2022-41725", + "VendorIDs": [ + "GO-2023-1569" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41725", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:344c01a95426ea0d0630ca6863971829bc3d86e1e90d5e7f666ecaf54dd67457", + "Title": "golang: net/http, mime/multipart: denial of service from excessive resource consumption", + "Description": "A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing \"up to maxMemory bytes +10MB (reserved for non-file parts) in memory\". File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did not properly account for all memory consumed by a parsed form, such as map entry overhead, part names, and MIME headers, permitting a maliciously crafted form to consume well over 10MB. In addition, ReadForm contained no limit on the number of disk files created, permitting a relatively small request body to create a large number of disk temporary files. With fix, ReadForm now properly accounts for various forms of memory overhead, and should now stay within its documented limit of 10MB + maxMemory bytes of memory consumption. Users should still be aware that this limit is high and may still be hazardous. In addition, ReadForm now creates at most one on-disk temporary file, combining multiple form parts into a single temporary file. The mime/multipart.File interface type's documentation states, \"If stored on disk, the File's underlying concrete type will be an *os.File.\". This is no longer the case when a form contains more than one file part, due to this coalescing of parts into a single file. The previous behavior of using distinct files for each form part may be reenabled with the environment variable GODEBUG=multipartfiles=distinct. Users should be aware that multipart.ReadForm and the http.Request methods that call it do not limit the amount of disk consumed by temporary files. Callers can limit the size of form data with http.MaxBytesReader.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41725", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/5c55ac9bf1e5f779220294c843526536605f42ab%20%5B1.19%5D", + "https://go.dev/cl/468124", + "https://go.dev/issue/58006", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41725.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41725", + "https://pkg.go.dev/vuln/GO-2023-1569", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41725" + ], + "PublishedDate": "2023-02-28T18:15:10.12Z", + "LastModifiedDate": "2026-06-17T05:03:43.243Z" + }, + { + "VulnerabilityID": "CVE-2023-24534", + "VendorIDs": [ + "GO-2023-1704" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24534", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e45bcca5d70cdf1e3cf5b5e0adf772f3e7ef85349bc0980aa5b81153b1aec5bb", + "Title": "golang: net/http, net/textproto: denial of service from excessive memory allocation", + "Description": "HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more memory than required to hold the parsed headers. An attacker can exploit this behavior to cause an HTTP server to allocate large amounts of memory from a small request, potentially leading to memory exhaustion and a denial of service. With fix, header parsing now correctly allocates only the memory required to hold parsed headers.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24534", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/3991f6c41c7dfd167e889234c0cf1d840475e93c%20%28go1.20.3%29", + "https://github.com/golang/go/commit/d6759e7a059f4208f07aa781402841d7ddaaef96%20%28go1.19.8%29", + "https://go.dev/cl/481994", + "https://go.dev/issue/58975", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24534.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24534", + "https://pkg.go.dev/vuln/GO-2023-1704", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230526-0007/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24534" + ], + "PublishedDate": "2023-04-06T16:15:07.657Z", + "LastModifiedDate": "2026-06-17T05:39:28.893Z" + }, + { + "VulnerabilityID": "CVE-2023-24536", + "VendorIDs": [ + "GO-2023-1705" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24536", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:174538c2070e47dc30d5a5ff383bb2b471b2590b325bd5be8b3e11a546968705", + "Title": "golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption", + "Description": "Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems from several causes: 1. mime/multipart.Reader.ReadForm limits the total memory a parsed multipart form can consume. ReadForm can undercount the amount of memory consumed, leading it to accept larger inputs than intended. 2. Limiting total memory does not account for increased pressure on the garbage collector from large numbers of small allocations in forms with many parts. 3. ReadForm can allocate a large number of short-lived buffers, further increasing pressure on the garbage collector. The combination of these factors can permit an attacker to cause an program that parses multipart forms to consume large amounts of CPU and memory, potentially resulting in a denial of service. This affects programs that use mime/multipart.Reader.ReadForm, as well as form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. With fix, ReadForm now does a better job of estimating the memory consumption of parsed forms, and performs many fewer short-lived allocations. In addition, the fixed mime/multipart.Reader imposes the following limits on the size of parsed forms: 1. Forms parsed with ReadForm may contain no more than 1000 parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxparts=. 2. Form parts parsed with NextPart and NextRawPart may contain no more than 10,000 header fields. In addition, forms parsed with ReadForm may contain no more than 10,000 header fields across all parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxheaders=.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24536", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/7917b5f31204528ea72e0629f0b7d52b35b27538%20%28go.1.19.8%29", + "https://github.com/golang/go/commit/bf8c7c575c8a552d9d79deb29e80854dc88528d0%20%28go1.20.3%29", + "https://go.dev/cl/482075", + "https://go.dev/cl/482076", + "https://go.dev/cl/482077", + "https://go.dev/issue/59153", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24536.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24536", + "https://pkg.go.dev/vuln/GO-2023-1705", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230526-0007/", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24536" + ], + "PublishedDate": "2023-04-06T16:15:07.71Z", + "LastModifiedDate": "2026-06-17T05:39:29.287Z" + }, + { + "VulnerabilityID": "CVE-2023-24537", + "VendorIDs": [ + "GO-2023-1702" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24537", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c9a3a1a8a55dfc93a12e9b7157b4f44fb50f308a18c4ece14042898e65a1820f", + "Title": "golang: go/parser: Infinite loop in parsing", + "Description": "Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24537", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/126a1d02da82f93ede7ce0bd8d3c51ef627f2104%20%28go1.19.8%29", + "https://github.com/golang/go/commit/e7c4b07ecf6b367f1afc9cc48cde963829dd0aab%20%28go1.20.3%29", + "https://github.com/golang/go/issues/59180", + "https://go.dev/cl/482078", + "https://go.dev/issue/59180", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24537.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24537", + "https://pkg.go.dev/vuln/GO-2023-1702", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241129-0004/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24537" + ], + "PublishedDate": "2023-04-06T16:15:07.753Z", + "LastModifiedDate": "2026-06-17T05:39:29.483Z" + }, + { + "VulnerabilityID": "CVE-2023-24539", + "VendorIDs": [ + "GO-2023-1751" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24539", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9f3aa4b6522c93a82db44a5d43f1e522e739f7e40b56eaf36a7aebb7e1c596e1", + "Title": "golang: html/template: improper sanitization of CSS values", + "Description": "Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24539", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/090590fdccc8442728aa31601927da1bf2ef1288%20%28go1.20.4%29", + "https://github.com/golang/go/commit/e49282327b05192e46086bf25fd3ac691205fe80%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59720", + "https://go.dev/cl/491615", + "https://go.dev/issue/59720", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-24539.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24539", + "https://pkg.go.dev/vuln/GO-2023-1751", + "https://security.netapp.com/advisory/ntap-20241129-0005/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24539" + ], + "PublishedDate": "2023-05-11T16:15:09.6Z", + "LastModifiedDate": "2026-06-17T05:39:29.84Z" + }, + { + "VulnerabilityID": "CVE-2023-29400", + "VendorIDs": [ + "GO-2023-1753" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-29400", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6cf4fc8c9c2d1988021d6dd57bb622a9be7d9e348cd40eae497a81f8896ea932", + "Title": "golang: html/template: improper handling of empty HTML attributes", + "Description": "Templates containing actions in unquoted HTML attributes (e.g. \"attr={{.}}\") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-29400", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/337dd75343145b74ed2073d793322eb4103b56ad%20%28go1.20.4%29", + "https://github.com/golang/go/commit/9db0e74f606b8afb28cc71d4b1c8b4ed24cabbf5%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59722", + "https://go.dev/cl/491617", + "https://go.dev/issue/59722", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-29400.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-29400", + "https://pkg.go.dev/vuln/GO-2023-1753", + "https://security.netapp.com/advisory/ntap-20241213-0005/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-29400" + ], + "PublishedDate": "2023-05-11T16:15:09.85Z", + "LastModifiedDate": "2026-06-17T05:49:57.937Z" + }, + { + "VulnerabilityID": "CVE-2023-29403", + "VendorIDs": [ + "GO-2023-1840" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.10, 1.20.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-29403", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f0c9aa4a06e8675820fe2e78a37c6844478197d77ede9778f961fde413c5dd5d", + "Title": "golang: runtime: unexpected behavior of setuid/setgid binaries", + "Description": "On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-668" + ], + "VendorSeverity": { + "alma": 4, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 4, + "photon": 3, + "redhat": 3, + "rocky": 4, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:3923", + "https://access.redhat.com/security/cve/CVE-2023-29403", + "https://bugzilla.redhat.com/2216965", + "https://bugzilla.redhat.com/2217562", + "https://bugzilla.redhat.com/2217565", + "https://bugzilla.redhat.com/2217569", + "https://bugzilla.redhat.com/show_bug.cgi?id=2216965", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217562", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217565", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217569", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29402", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29403", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29404", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29405", + "https://errata.almalinux.org/9/ALSA-2023-3923.html", + "https://errata.rockylinux.org/RLSA-2023:3923", + "https://github.com/golang/go/commit/36144ba429ef2650940c72e7a0b932af3612d420%20%28go1.20.5%29", + "https://github.com/golang/go/commit/a7b1cd452ddc69a6606c2f35ac5786dc892e62cb%20%28go1.19.10%29", + "https://github.com/golang/go/issues/60272", + "https://go.dev/cl/501223", + "https://go.dev/issue/60272", + "https://groups.google.com/g/golang-announce/c/q5135a9d924", + "https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJ", + "https://linux.oracle.com/cve/CVE-2023-29403.html", + "https://linux.oracle.com/errata/ELSA-2023-3923.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZ2O6YCO2IZMZJELQGZYR2WAUNEDLYV6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XBS3IIK6ADV24C5ULQU55QLT2UE762ZX/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-29403", + "https://pkg.go.dev/vuln/GO-2023-1840", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241220-0009/", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2023-29403" + ], + "PublishedDate": "2023-06-08T21:15:16.927Z", + "LastModifiedDate": "2026-06-17T05:49:58.43Z" + }, + { + "VulnerabilityID": "CVE-2023-39325", + "VendorIDs": [ + "GHSA-4374-p667-p6c8", + "GO-2023-2102" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.10, 1.21.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-39325", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5f0cfa28fee50e20fc884730f35945a04e879faec4329546f837ea0aee8f2129", + "Title": "golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)", + "Description": "A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "bottlerocket": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39325", + "https://access.redhat.com/errata/RHSA-2023:6077", + "https://access.redhat.com/security/cve/CVE-2023-39325", + "https://access.redhat.com/security/cve/CVE-2023-44487", + "https://bugzilla.redhat.com/2242803", + "https://bugzilla.redhat.com/2243296", + "https://bugzilla.redhat.com/show_bug.cgi?id=2242803", + "https://bugzilla.redhat.com/show_bug.cgi?id=2243296", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39325", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44487", + "https://errata.almalinux.org/9/ALSA-2023-6077.html", + "https://errata.rockylinux.org/RLSA-2023:6077", + "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-48vh-q3rp-4grw", + "https://github.com/golang/go/commit/24ae2d927285c697440fdde3ad7f26028354bcf3%20%5Bgolang-%201.21%5D", + "https://github.com/golang/go/commit/e175f27f58aa7b9cd4d79607ae65d2cd5baaee68%20%5Bgolang-1.20%5D", + "https://github.com/golang/go/issues/63417", + "https://go.dev/cl/534215", + "https://go.dev/cl/534235", + "https://go.dev/issue/63417", + "https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ", + "https://linux.oracle.com/cve/CVE-2023-39325.html", + "https://linux.oracle.com/errata/ELSA-2023-5867.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3OVW5V2DM5K5IC3H7O42YDUGNJ74J35O/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3SZN67IL7HMGMNAVLOTIXLIHUDXZK4LH/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WJ4QVX2AMUJ2F2S27POOAHRC4K3CHU4/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5RSKA2II6QTD4YUKUNDVJQSRYSFC4VFR/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVZDNSMVDAQJ64LJC5I5U5LDM5753647/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2BBIDR2ZMB3X5BC7SR4SLQMHRMVPY6L/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECRC75BQJP6FJN2L7KCKYZW4DSBD7QSD/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FTMJ3NJIDAZFWJQQSP3L22MUFJ3UP2PT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSY7SXFFTPZFWDM6XELSDSHZLVW3AHK7/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HZQIELEIRSZUYTFFH5KTH2YJ4IIQG2KE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPWCNYB5PQ5PCVZ4NJT6G56ZYFZ5QBU6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5E5JSJBZLYXOTZWXHJKRVCIXIHVWKJ6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZQYOOKHQDQ57LV2IAG6NRFOVXKHJJ3Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NG7IMPL55MVWU3LCI4JQJT3K2U5CHDV7/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ODBY7RVMGZCBSTWF2OZGIZS57FNFUL67/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXGWPQOJ3JNDW2XIYKIVJ7N7QUIFNM2Q/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PJCUNGIQDUMZ4Z6HWVYIMR66A35F5S74/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QF5QSYAOPDOWLY6DUHID56Q4HQFYB45I/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXOU2JZUBEBP7GBKAYIJRPRBZSJCD7ST/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3UETKPUB3V5JS5TLZOF3SMTGT5K5APS/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULQQONMSCQSH5Z5OWFFQHCGEZ3NL4DRJ/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTT7DG3QOF5ZNJLUGHDNLRUIN6OWZARP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2LZSWTV4NV4SNQARNXG5T6LRHP26EW2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WCNCBYKZXLDFGAJUB7ZP5VLC3YTHJNVH/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XTNLSL44Y5FB6JWADSZH6DCV4JJAAEQY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJWHBLVZDM5KQSDFRBFRKU5KSSOLIRQ4/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRKEXKANQ7BKJW2YTAMP625LJUJZLJ4P/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZSVEMQV5ROY5YW5QE3I57HT3ITWG5GCV/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-39325", + "https://pkg.go.dev/vuln/GO-2023-2102", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20231110-0008/", + "https://ubuntu.com/security/notices/USN-6574-1", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487", + "https://www.cve.org/CVERecord?id=CVE-2023-39325" + ], + "PublishedDate": "2023-10-11T22:15:09.88Z", + "LastModifiedDate": "2026-06-17T06:12:02.173Z" + }, + { + "VulnerabilityID": "CVE-2023-45283", + "VendorIDs": [ + "GO-2023-2185" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.11, 1.21.4, 1.20.12, 1.21.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3369192edcc981d9e2a6d88698fc1c50f55d6d6792bbb567a28f280cf8d4abf9", + "Title": "The filepath package does not recognize paths with a \\??\\ prefix as sp ...", + "Description": "The filepath package does not recognize paths with a \\??\\ prefix as special. On Windows, a path beginning with \\??\\ is a Root Local Device path equivalent to a path beginning with \\\\?\\. Paths with a \\??\\ prefix may be used to access arbitrary locations on the system. For example, the path \\??\\c:\\x is equivalent to the more common path c:\\x. Before fix, Clean could convert a rooted path such as \\a\\..\\??\\b into the root local device path \\??\\b. Clean will now convert this to .\\??\\b. Similarly, Join(\\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \\??\\b. Join will now convert this to \\.\\??\\b. In addition, with fix, IsAbs now correctly reports paths beginning with \\??\\ as absolute, and VolumeName correctly reports the \\??\\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \\?, resulting in filepath.Clean(\\?\\c:) returning \\?\\c: rather than \\?\\c:\\ (among other effects). The previous behavior has been restored.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "amazon": 2, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2023/12/05/2", + "https://go.dev/cl/540277", + "https://go.dev/cl/541175", + "https://go.dev/issue/63713", + "https://go.dev/issue/64028", + "https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY", + "https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45283", + "https://pkg.go.dev/vuln/GO-2023-2185", + "https://security.netapp.com/advisory/ntap-20231214-0008/" + ], + "PublishedDate": "2023-11-09T17:15:08.757Z", + "LastModifiedDate": "2026-06-17T06:28:34.863Z" + }, + { + "VulnerabilityID": "CVE-2023-45287", + "VendorIDs": [ + "GO-2023-2375" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45287", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:835312812f9d81d162fd541c3c955fb773f51abf05f4f786ae7b22320db5f59c", + "Title": "golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.", + "Description": "Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-203" + ], + "VendorSeverity": { + "alma": 2, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:2272", + "https://access.redhat.com/errata/RHSA-2024:2988", + "https://access.redhat.com/security/cve/CVE-2023-45287", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/2253330", + "https://bugzilla.redhat.com/show_bug.cgi?id=1983596", + "https://bugzilla.redhat.com/show_bug.cgi?id=1989575", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237773", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237776", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2244340", + "https://bugzilla.redhat.com/show_bug.cgi?id=2246840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2253330", + "https://bugzilla.redhat.com/show_bug.cgi?id=2254210", + "https://bugzilla.redhat.com/show_bug.cgi?id=2262272", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25091", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33198", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29409", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39318", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39319", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39326", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45287", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23650", + "https://errata.almalinux.org/9/ALSA-2024-2272.html", + "https://errata.rockylinux.org/RLSA-2024:2988", + "https://go.dev/cl/326012/26", + "https://go.dev/issue/20654", + "https://groups.google.com/g/golang-announce/c/QMK8IQALDvA", + "https://linux.oracle.com/cve/CVE-2023-45287.html", + "https://linux.oracle.com/errata/ELSA-2024-2988.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45287", + "https://people.redhat.com/~hkario/marvin/", + "https://pkg.go.dev/vuln/GO-2023-2375", + "https://security.netapp.com/advisory/ntap-20240112-0005/", + "https://www.cve.org/CVERecord?id=CVE-2023-45287" + ], + "PublishedDate": "2023-12-05T17:15:08.57Z", + "LastModifiedDate": "2026-06-17T06:28:35.46Z" + }, + { + "VulnerabilityID": "CVE-2023-45288", + "VendorIDs": [ + "GHSA-4v7x-pqxf-cx7m", + "GO-2024-2687" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.21.9, 1.22.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45288", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:35e2fbf8436ea3d739bca0d9ae1bdc8c603e69e335322c63e682ced3ed318869", + "Title": "golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS", + "Description": "An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "bottlerocket": 2, + "cbl-mariner": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288", + "http://www.openwall.com/lists/oss-security/2024/04/03/16", + "http://www.openwall.com/lists/oss-security/2024/04/05/4", + "https://access.redhat.com/errata/RHSA-2024:2724", + "https://access.redhat.com/security/cve/CVE-2023-45288", + "https://bugzilla.redhat.com/2268017", + "https://bugzilla.redhat.com/2268018", + "https://bugzilla.redhat.com/2268019", + "https://bugzilla.redhat.com/2268273", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268017", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268018", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268019", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268273", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45289", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45290", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24783", + "https://errata.almalinux.org/9/ALSA-2024-2724.html", + "https://errata.rockylinux.org/RLSA-2024:2724", + "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-c9wf-j9h6-m2r9", + "https://go.dev/cl/576155", + "https://go.dev/issue/65051", + "https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M", + "https://kb.cert.org/vuls/id/421644", + "https://linux.oracle.com/cve/CVE-2023-45288.html", + "https://linux.oracle.com/errata/ELSA-2024-3346.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRYFHIQ6XRKRYBI2F5UESH67BJBQXUPT/", + "https://nowotarski.info/http2-continuation-flood/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45288", + "https://pkg.go.dev/vuln/GO-2024-2687", + "https://security.netapp.com/advisory/ntap-20240419-0009/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2023-45288", + "https://www.kb.cert.org/vuls/id/421644" + ], + "PublishedDate": "2024-04-04T21:15:16.113Z", + "LastModifiedDate": "2026-06-17T06:28:35.58Z" + }, + { + "VulnerabilityID": "CVE-2024-34156", + "VendorIDs": [ + "GO-2024-3106" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.22.7, 1.23.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-34156", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1eae12c045cd78d3e553c672b7df266b4e4633ccec1ff5b0af855f435a4cafd4", + "Title": "encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion", + "Description": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:3773", + "https://access.redhat.com/security/cve/CVE-2024-34156", + "https://bugzilla.redhat.com/2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341750", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341751", + "https://bugzilla.redhat.com/show_bug.cgi?id=2344219", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866", + "https://errata.almalinux.org/9/ALSA-2025-3773.html", + "https://errata.rockylinux.org/RLSA-2025:3773", + "https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01%20%28go1.22.7%29", + "https://github.com/golang/go/commit/fa8ff1a46deb6c816304441ec6740ec112e19012%20%28go1.23.1%29", + "https://go.dev/cl/611239", + "https://go.dev/issue/69139", + "https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc", + "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk", + "https://linux.oracle.com/cve/CVE-2024-34156.html", + "https://linux.oracle.com/errata/ELSA-2025-3773.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-34156", + "https://pkg.go.dev/vuln/GO-2024-3106", + "https://security.netapp.com/advisory/ntap-20240926-0004/", + "https://ubuntu.com/security/notices/USN-7081-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2024-34156" + ], + "PublishedDate": "2024-09-06T21:15:12.02Z", + "LastModifiedDate": "2026-06-17T07:33:00.72Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b64040c9defb63af53717e091e3e765db1cceb8218d36cb2c04bd4418b29010b", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-08-14T13:17:15.67Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:72c45244070035a0666c83082d2017b3329aee96b61865c5c0ec5293fe8bd5da", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ff1dae2a8d13d773d627feb6c0dd0a8ba689c7c1e720dbeadf020ceb9dae8881", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-08-14T13:17:46.517Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:01e0472ddc52a6073354fda03d6e0e7bbac37e70111a2012421d19efe218d97f", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-08-14T13:17:49.537Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6d5899d8660afa00926984d792f4d12b2b3325adfd5d3ef81a5ec666562fffa3", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-08-14T13:17:52.587Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3904546df040a9d179911af359aebc4ae24ac728701369658fe1bdad33961050", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d6575a027747d95e0e1352eb71b983fce9bb640174cb4c5d49e93f5b85eb47df", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-33722.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-08-14T13:17:54.66Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:24e015955c3448a3ff601b663901757c845b4ff5a3c79fedbfc06d9ce18e7fb1", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:39319", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-39573.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-08-14T13:18:12Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:e75f52a0327015732dcc34549866f425a8386e0be854f8e320332bcd77d31a2d", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-08-13T13:18:25.52Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3b7c97735314e473fb935f326f2db627c431c29be19d0a5da3999ca2ad9f4a15", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-08-14T16:16:55.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2b72c6b14e3326216056716ad9ba96baa10a5d8cb4d8615ab1fb2c491524c138", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-08-14T13:18:23.657Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:bccc1dcd2507071c0ef5cbf685efec56c2f2527840acd87f5dbf9d8e91b40779", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:37435", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-08-14T13:18:24.667Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:eb10eed81398b5a01379d1064e58710edb6d1dbfb40624b67502e1bef20a42ef", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9417bd1255ef815569548a5d8a26e8d7d8a63f45a1208a53986f4621c41804da", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:68588d025c8d504ef0954847731d9a62123d382580df3bfad5f56e38ad1cbb75", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-08-14T13:18:47.497Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5abba523232d1d296236fc4ae90d6f8df97146ac429878fe73c7e1ac31f44c1a", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d247e44f22a83b3e18bceeefdc3a8bbf8a89edc161fe5c485bad6c1e17650121", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-08-14T16:16:57.21Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7647a909623504aec48bde6371f57eb1d4a13200c4c45ebf5158a7dc28b477f9", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-08-14T16:16:57.367Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:90c7f69ae2b7c6392ab5460a7c2c9c29ae5ae69b93b75e9557a08e56ae8a6f8f", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-08-14T16:16:57.523Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ff05bf42a5d924c1dd47d1bc93fa11c8c06afff164303f658d9a9698d2f3f235", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-08-14T17:19:13.91Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "5f237a6a410be2dd" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:07698674fdc20b7e17e1e24a127c0ada08d60a87b32a39121187e835fbe0c0e3", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-08-14T16:16:57.717Z" + }, + { + "VulnerabilityID": "CVE-2022-32149", + "VendorIDs": [ + "GHSA-69ch-w2m2-3vjp", + "GO-2022-1059" + ], + "PkgID": "golang.org/x/text@v0.3.7", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.3.7", + "UID": "8da568af3f56791d" + }, + "InstalledVersion": "v0.3.7", + "FixedVersion": "0.3.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-32149", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:91af3f0672dde168b77fd5b71551450907c92b526dc0854b41ad37936c5fb2a5", + "Title": "golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags", + "Description": "An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-772" + ], + "VendorSeverity": { + "azure": 3, + "cbl-mariner": 3, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-32149", + "https://github.com/golang/text/commit/434eadcdbc3b0256971992e8c70027278364c72c%20%28v0.3.8%29", + "https://go.dev/cl/442235", + "https://go.dev/issue/56152", + "https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ", + "https://groups.google.com/g/golang-dev/c/qfPIly0X7aU", + "https://nvd.nist.gov/vuln/detail/CVE-2022-32149", + "https://pkg.go.dev/vuln/GO-2022-1059", + "https://security.netapp.com/advisory/ntap-20230203-0006/", + "https://ubuntu.com/security/notices/USN-5873-1", + "https://www.cve.org/CVERecord?id=CVE-2022-32149" + ], + "PublishedDate": "2022-10-14T15:15:34.543Z", + "LastModifiedDate": "2026-06-17T04:46:45.967Z" + }, + { + "VulnerabilityID": "CVE-2026-56852", + "VendorIDs": [ + "GO-2026-5970" + ], + "PkgID": "golang.org/x/text@v0.3.7", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.3.7", + "UID": "8da568af3f56791d" + }, + "InstalledVersion": "v0.3.7", + "FixedVersion": "0.39.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56852", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:96990c7c878b51ea20ddbc11fd93d2fbd59ccadb84c14189edfc8bf9dbf0a90d", + "Title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input", + "Description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56852", + "https://go.dev/cl/794100", + "https://go.dev/issue/80142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56852", + "https://pkg.go.dev/vuln/GO-2026-5970", + "https://www.cve.org/CVERecord?id=CVE-2026-56852" + ], + "PublishedDate": "2026-07-21T20:17:02.867Z", + "LastModifiedDate": "2026-07-23T18:27:48.877Z" + }, + { + "VulnerabilityID": "CVE-2022-23806", + "VendorIDs": [ + "GO-2021-0319" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.14, 1.17.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23806", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:cf57d2dc1ec2eaf7ba334e3903218d3937851b682961b5c9488628d34fdc0be8", + "Title": "golang: crypto/elliptic: IsOnCurve returns true for invalid field elements", + "Description": "Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-252" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V3Score": 9.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V2Score": 6.4, + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2022-23806", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/382455", + "https://go.dev/issue/50974", + "https://go.googlesource.com/go/+/7f9494c277a471f6f47f4af3036285c0b1419816", + "https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ", + "https://linux.oracle.com/cve/CVE-2022-23806.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23806", + "https://pkg.go.dev/vuln/GO-2021-0319", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220225-0006/", + "https://www.cve.org/CVERecord?id=CVE-2022-23806", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-02-11T01:15:07.747Z", + "LastModifiedDate": "2026-06-17T04:30:48.69Z" + }, + { + "VulnerabilityID": "CVE-2023-24538", + "VendorIDs": [ + "GO-2023-1703" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24538", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d6fe11e727e7c2c362a4a3da73097d5405f7d9b1a28e17c39d774e852980aa15", + "Title": "golang: html/template: backticks not treated as string delimiters", + "Description": "Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. \"var a = {{.}}\"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24538", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/20374d1d759bc4e17486bde1cb9dca5be37d9e52%20%28go1.20.3%29", + "https://github.com/golang/go/commit/b1e3ecfa06b67014429a197ec5e134ce4303ad9b%20%28go1.19.8%29", + "https://github.com/golang/go/issues/59234", + "https://go.dev/cl/482079", + "https://go.dev/issue/59234", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24538.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24538", + "https://pkg.go.dev/vuln/GO-2023-1703", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241115-0007/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24538" + ], + "PublishedDate": "2023-04-06T16:15:07.8Z", + "LastModifiedDate": "2026-06-17T05:39:29.67Z" + }, + { + "VulnerabilityID": "CVE-2023-24540", + "VendorIDs": [ + "GO-2023-1752" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24540", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:daaa597b8f2d414c49b31d7f6e52b5234a30d7a02f26900a235b30aecbdcb37a", + "Title": "golang: html/template: improper handling of JavaScript whitespace", + "Description": "Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set \"\\t\\n\\f\\r\\u0020\\u2028\\u2029\" in JavaScript contexts that also contain actions may not be properly sanitized during execution.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-77" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24540", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/4a28cad66655ee01c6e944271e23c33cab021765%20%28go1.20.4%29", + "https://github.com/golang/go/commit/ce7bd33345416e6d8cac901792060591cafc2797%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59721", + "https://go.dev/cl/491616", + "https://go.dev/issue/59721", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-24540.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24540", + "https://pkg.go.dev/vuln/GO-2023-1752", + "https://security.netapp.com/advisory/ntap-20241115-0008/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24540" + ], + "PublishedDate": "2023-05-11T16:15:09.687Z", + "LastModifiedDate": "2026-06-17T05:39:30.007Z" + }, + { + "VulnerabilityID": "CVE-2024-24790", + "VendorIDs": [ + "GO-2024-2887" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.21.11, 1.22.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-24790", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f4aac283c7da42deb86d3728852c10b9fb975d9397dc7d21098e32a839a18f9d", + "Title": "golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses", + "Description": "The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.", + "Severity": "CRITICAL", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 4, + "bottlerocket": 2, + "cbl-mariner": 4, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.7 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "http://www.openwall.com/lists/oss-security/2024/06/04/1", + "https://access.redhat.com/errata/RHSA-2025:7256", + "https://access.redhat.com/security/cve/CVE-2024-24790", + "https://bugzilla.redhat.com/2237777", + "https://bugzilla.redhat.com/2237778", + "https://bugzilla.redhat.com/2279814", + "https://bugzilla.redhat.com/2292787", + "https://bugzilla.redhat.com/2295310", + "https://bugzilla.redhat.com/2315719", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2279814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2292787", + "https://bugzilla.redhat.com/show_bug.cgi?id=2295310", + "https://bugzilla.redhat.com/show_bug.cgi?id=2315719", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24788", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24790", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24791", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9355", + "https://errata.almalinux.org/9/ALSA-2025-7256.html", + "https://errata.rockylinux.org/RLSA-2025:7256", + "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/2.9.0/BRSA-glvb5gspjgq6.toml", + "https://github.com/golang/go/commit/051bdf3fd12a40307606ff9381138039c5f452f0%20%281.21%29", + "https://github.com/golang/go/commit/12d5810cdb1f73cf23d7a86462143e9463317fca%20%281.22%29", + "https://github.com/golang/go/issues/67680", + "https://go.dev/cl/590316", + "https://go.dev/issue/67680", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k", + "https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ", + "https://linux.oracle.com/cve/CVE-2024-24790.html", + "https://linux.oracle.com/errata/ELSA-2025-7256.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-24790", + "https://pkg.go.dev/vuln/GO-2024-2887", + "https://security.netapp.com/advisory/ntap-20240905-0002/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2024-24790" + ], + "PublishedDate": "2024-06-05T16:15:10.56Z", + "LastModifiedDate": "2026-06-17T07:14:52.097Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8c0273859b4c26ac7acd3de267856938de83873532517b3ff68ceada42c5ee41", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2021-39293", + "VendorIDs": [ + "GO-2022-0273" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.8, 1.17.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-39293", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6ce74b56332ce47b4179bd832e44600a1b68c5b90a4becc77128525664f4902f", + "Title": "golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196)", + "Description": "In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-39293", + "https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/343434", + "https://go.dev/issue/47801", + "https://go.googlesource.com/go/+/bacbc33439b124ffd7392c91a5f5d96eca8c0c0b", + "https://groups.google.com/g/golang-announce/c/dx9d7IOseHw", + "https://linux.oracle.com/cve/CVE-2021-39293.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-39293", + "https://pkg.go.dev/vuln/GO-2022-0273", + "https://security.netapp.com/advisory/ntap-20220217-0009/", + "https://www.cve.org/CVERecord?id=CVE-2021-39293" + ], + "PublishedDate": "2022-01-24T01:15:07.92Z", + "LastModifiedDate": "2026-06-17T04:03:28.747Z" + }, + { + "VulnerabilityID": "CVE-2021-41771", + "VendorIDs": [ + "GO-2021-0263" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.10, 1.17.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-41771", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:835a4191a1d2132623f005c909e1789bd47cb03cecb18b9e60d64019cf45a2df", + "Title": "golang: debug/macho: invalid dynamic symbol table command can cause panic", + "Description": "ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-119" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-41771", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/367075", + "https://go.dev/issue/48990", + "https://go.googlesource.com/go/+/61536ec03063b4951163bd09609c86d82631fa27", + "https://groups.google.com/g/golang-announce/c/0fM21h43arc", + "https://linux.oracle.com/cve/CVE-2021-41771.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4OFS3M3OFB24SWPTIAPARKGPUMQVUY6Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ON7BQRRJZBOR5TJHURBAB3WLF4YXFC6Z/", + "https://nvd.nist.gov/vuln/detail/CVE-2021-41771", + "https://pkg.go.dev/vuln/GO-2021-0263", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20211210-0003/", + "https://www.cve.org/CVERecord?id=CVE-2021-41771", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-11-08T06:15:08.057Z", + "LastModifiedDate": "2026-06-17T04:08:53.673Z" + }, + { + "VulnerabilityID": "CVE-2021-41772", + "VendorIDs": [ + "GO-2021-0264" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.10, 1.17.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-41772", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b79afc8c3ac900b8612e9287153fe3a6f44316049e459fc12f9fa5e19af269d7", + "Title": "golang: archive/zip: Reader.Open panics on empty string", + "Description": "Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2021-41772", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/349770", + "https://go.dev/issue/48085", + "https://go.googlesource.com/go/+/b24687394b55a93449e2be4e6892ead58ea9a10f", + "https://groups.google.com/g/golang-announce/c/0fM21h43arc", + "https://linux.oracle.com/cve/CVE-2021-41772.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4OFS3M3OFB24SWPTIAPARKGPUMQVUY6Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ON7BQRRJZBOR5TJHURBAB3WLF4YXFC6Z/", + "https://nvd.nist.gov/vuln/detail/CVE-2021-41772", + "https://pkg.go.dev/vuln/GO-2021-0264", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20211210-0003/", + "https://www.cve.org/CVERecord?id=CVE-2021-41772", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-11-08T06:15:08.107Z", + "LastModifiedDate": "2026-06-17T04:08:53.8Z" + }, + { + "VulnerabilityID": "CVE-2021-44716", + "VendorIDs": [ + "GHSA-vc3p-29h2-gpcp", + "GO-2022-0288" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.12, 1.17.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-44716", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f9ba529e65e7e3944dde4729e2fd0d0e0b240ee018900196b09504d14cd2bb38", + "Title": "golang: net/http: limit growth of header canonicalization cache", + "Description": "net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:0001", + "https://access.redhat.com/security/cve/CVE-2021-44716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2030801", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44716", + "https://errata.rockylinux.org/RLSA-2022:0001", + "https://github.com/golang/go/commit/48d948963c5ce7add72af5665a871caff6c1d35a%20%28go1.17.5%29", + "https://github.com/golang/net/commit/491a49abca63de5e07ef554052d180a1b5fe2d70", + "https://go.dev/cl/369794", + "https://go.dev/issue/50058", + "https://groups.google.com/g/golang-announce/c/hcmEScgc00k", + "https://groups.google.com/g/golang-announce/c/hcmEScgc00k/m/ZWnOjeY4CQAJ", + "https://linux.oracle.com/cve/CVE-2021-44716.html", + "https://linux.oracle.com/errata/ELSA-2022-0001.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html", + "https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-44716", + "https://pkg.go.dev/vuln/GO-2022-0288", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220121-0002/", + "https://www.cve.org/CVERecord?id=CVE-2021-44716" + ], + "PublishedDate": "2022-01-01T05:15:08.307Z", + "LastModifiedDate": "2026-06-17T04:12:45.48Z" + }, + { + "VulnerabilityID": "CVE-2022-23772", + "VendorIDs": [ + "GO-2021-0317" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.14, 1.17.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-23772", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1ef6f97414936d95e1a52e566d05f51c117a81c8e61935d2a3450cea8967df82", + "Title": "golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString", + "Description": "Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:C", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 7.8, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-38297.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-39293.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41771.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-41772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23772.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23773.json", + "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-23806.json", + "https://access.redhat.com/security/cve/CVE-2022-23772", + "https://errata.almalinux.org/8/ALSA-2022-1819.html", + "https://go.dev/cl/379537", + "https://go.dev/issue/50699", + "https://go.googlesource.com/go/+/ad345c265916bbf6c646865e4642eafce6d39e78", + "https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ", + "https://linux.oracle.com/cve/CVE-2022-23772.html", + "https://linux.oracle.com/errata/ELSA-2022-1819.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-23772", + "https://pkg.go.dev/vuln/GO-2021-0317", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220225-0006/", + "https://www.cve.org/CVERecord?id=CVE-2022-23772", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2022-02-11T01:15:07.657Z", + "LastModifiedDate": "2026-06-17T04:30:46.407Z" + }, + { + "VulnerabilityID": "CVE-2022-24675", + "VendorIDs": [ + "GO-2022-0433" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.9, 1.18.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-24675", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d01ae11ad30f97764c61ad8a6f2313b2293ff53c86e88f351b136ad90111539f", + "Title": "golang: encoding/pem: fix stack overflow in Decode", + "Description": "encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-24675", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/399820", + "https://go.dev/issue/51853", + "https://go.googlesource.com/go/+/45c3387d777caf28f4b992ad9a6216e3085bb8fe", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/oecdBNLOml8", + "https://linux.oracle.com/cve/CVE-2022-24675.html", + "https://linux.oracle.com/errata/ELSA-2022-5337.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TYZC4OAY54TO75FBEFAPV5G7O4D5TM/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F3BMW5QGX53CMIJIZWKXFKBJX2C5GWTY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RCRSABD6CUDIZULZPZL5BJ3ET3A2NEJP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-24675", + "https://pkg.go.dev/vuln/GO-2022-0433", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220915-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-24675" + ], + "PublishedDate": "2022-04-20T10:15:07.93Z", + "LastModifiedDate": "2026-06-17T04:32:16.51Z" + }, + { + "VulnerabilityID": "CVE-2022-24921", + "VendorIDs": [ + "GO-2021-0347" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.16.15, 1.17.8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-24921", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:eaf62ebad4c81c096abeaa379941ed9db8280118c951b8309107caf27757ca3d", + "Title": "golang: regexp: stack exhaustion via a deeply nested expression", + "Description": "regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-24921", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/384616", + "https://go.dev/issue/51112", + "https://go.googlesource.com/go/+/452f24ae94f38afa3704d4361d91d51218405c0a", + "https://groups.google.com/g/golang-announce/c/RP1hfrBYVuk", + "https://linux.oracle.com/cve/CVE-2022-24921.html", + "https://linux.oracle.com/errata/ELSA-2022-9363.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00017.html", + "https://lists.debian.org/debian-lts-announce/2022/04/msg00018.html", + "https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-24921", + "https://pkg.go.dev/vuln/GO-2021-0347", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220325-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-24921" + ], + "PublishedDate": "2022-03-05T20:15:08.323Z", + "LastModifiedDate": "2026-06-17T04:32:47.957Z" + }, + { + "VulnerabilityID": "CVE-2022-27664", + "VendorIDs": [ + "GHSA-69cg-p879-7622", + "GO-2022-0969" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.6, 1.19.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-27664", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f5b8ca1c7c21893e4546da56ab40ac7ce41330c3dd1f67754b8086d916a92627", + "Title": "golang: net/http: handle server errors after sending GOAWAY", + "Description": "In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:2177", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-27664", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2124669", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27664", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2023:2177", + "https://github.com/golang/go/commit/5bc9106458fc07851ac324a4157132a91b1f3479%20%28go1.18.6%29", + "https://github.com/golang/go/commit/9cfe4e258b1c9d4a04a42539c21c7bdb2e227824%20%28go1.19.1%29", + "https://github.com/golang/go/issues/54658", + "https://go.dev/cl/428735", + "https://go.dev/issue/54658", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s", + "https://groups.google.com/g/golang-announce/c/x49AQzIVX-s/m/0tgO0pjiBQAJ", + "https://linux.oracle.com/cve/CVE-2022-27664.html", + "https://linux.oracle.com/errata/ELSA-2024-0121.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-27664", + "https://pkg.go.dev/vuln/GO-2022-0969", + "https://security.gentoo.org/glsa/202209-26", + "https://security.netapp.com/advisory/ntap-20220923-0004/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-8089-1", + "https://ubuntu.com/security/notices/USN-8089-2", + "https://ubuntu.com/security/notices/USN-8089-3", + "https://www.cve.org/CVERecord?id=CVE-2022-27664" + ], + "PublishedDate": "2022-09-06T18:15:12.747Z", + "LastModifiedDate": "2026-06-17T04:37:26.873Z" + }, + { + "VulnerabilityID": "CVE-2022-28131", + "VendorIDs": [ + "GO-2022-0521" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-28131", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9852aa885166d39e7fa4c8aeb7ef7b0d7846608c77fcc8f48b328a8d171db65b", + "Title": "golang: encoding/xml: stack exhaustion in Decoder.Skip", + "Description": "Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8057", + "https://access.redhat.com/security/cve/CVE-2022-28131", + "https://bugzilla.redhat.com/2044628", + "https://bugzilla.redhat.com/2045880", + "https://bugzilla.redhat.com/2050648", + "https://bugzilla.redhat.com/2050742", + "https://bugzilla.redhat.com/2050743", + "https://bugzilla.redhat.com/2065290", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107376", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2107390", + "https://bugzilla.redhat.com/2107392", + "https://bugzilla.redhat.com/show_bug.cgi?id=2044628", + "https://bugzilla.redhat.com/show_bug.cgi?id=2045880", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050648", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050742", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2055349", + "https://bugzilla.redhat.com/show_bug.cgi?id=2065290", + "https://bugzilla.redhat.com/show_bug.cgi?id=2104367", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23648", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21698", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21702", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21713", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2022-8057.html", + "https://errata.rockylinux.org/RLSA-2022:8057", + "https://github.com/golang/go/commit/90f040ec510dd678b7860d70ca77e5682f4c7e96", + "https://go.dev/cl/417062", + "https://go.dev/issue/53614", + "https://go.googlesource.com/go/+/08c46ed43d80bbb67cb904944ea3417989be4af3", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-28131.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-28131", + "https://pkg.go.dev/vuln/GO-2022-0521", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-28131" + ], + "PublishedDate": "2022-08-10T20:15:32.767Z", + "LastModifiedDate": "2026-06-17T04:38:02.23Z" + }, + { + "VulnerabilityID": "CVE-2022-28327", + "VendorIDs": [ + "GO-2022-0435" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.9, 1.18.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-28327", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8a1448203a85d816c67f2e9cb867f2c11cb0e5fd5440b04e2c9cfe827c888322", + "Title": "golang: crypto/elliptic: panic caused by oversized scalar", + "Description": "The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:5799", + "https://access.redhat.com/security/cve/CVE-2022-28327", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24675", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28327", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29526", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30629", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.rockylinux.org/RLSA-2022:5799", + "https://go.dev/cl/397135", + "https://go.dev/issue/52075", + "https://go.googlesource.com/go/+/37065847d87df92b5eb246c88ba2085efcf0b331", + "https://groups.google.com/g/golang-announce", + "https://groups.google.com/g/golang-announce/c/oecdBNLOml8", + "https://linux.oracle.com/cve/CVE-2022-28327.html", + "https://linux.oracle.com/errata/ELSA-2022-5337.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42TYZC4OAY54TO75FBEFAPV5G7O4D5TM/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F3BMW5QGX53CMIJIZWKXFKBJX2C5GWTY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NY6GEAJMNKKMU5H46QO4D7D6A24KSPXE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RCRSABD6CUDIZULZPZL5BJ3ET3A2NEJP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-28327", + "https://pkg.go.dev/vuln/GO-2022-0435", + "https://security.gentoo.org/glsa/202208-02", + "https://security.netapp.com/advisory/ntap-20220915-0010/", + "https://www.cve.org/CVERecord?id=CVE-2022-28327" + ], + "PublishedDate": "2022-04-20T10:15:08.03Z", + "LastModifiedDate": "2026-06-17T04:38:23.653Z" + }, + { + "VulnerabilityID": "CVE-2022-2879", + "VendorIDs": [ + "GO-2022-1037" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-2879", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ac20c5827695358a4099446099d6c695cb2474cb556b26b2e01262a84c8b2250", + "Title": "golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers", + "Description": "Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2204", + "https://access.redhat.com/security/cve/CVE-2022-2879", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132867", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2204.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/0a723816cd205576945fa57fbdde7e6532d59d08%20%28go1.18.7%29", + "https://github.com/golang/go/commit/4fa773cdefd20be093c84f731be7d4febf5536fa%20%28go1.19.2%29", + "https://github.com/golang/go/issues/54853", + "https://github.com/vbatts/tar-split/releases/tag/v0.12.1", + "https://go.dev/cl/439355", + "https://go.dev/issue/54853", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-2879.html", + "https://linux.oracle.com/errata/ELSA-2024-2988.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-2879", + "https://pkg.go.dev/vuln/GO-2022-1037", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-2879" + ], + "PublishedDate": "2022-10-14T15:15:17.647Z", + "LastModifiedDate": "2026-06-17T04:42:45.443Z" + }, + { + "VulnerabilityID": "CVE-2022-2880", + "VendorIDs": [ + "GO-2022-1038" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-2880", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:21d51aa528329adfa76ab5522967267611b8fe31f920f34e84990ee7613952c9", + "Title": "golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters", + "Description": "Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-444" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-2880", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/9d2c73a9fd69e45876509bb3bdb2af99bf77da1e%20%28go1.18.7%29", + "https://github.com/golang/go/commit/f6d844510d5f1e3b3098eba255d9b633d45eac3b%20%28go1.19.2%29", + "https://github.com/golang/go/issues/54663", + "https://go.dev/cl/432976", + "https://go.dev/issue/54663", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-2880.html", + "https://linux.oracle.com/errata/ELSA-2024-3254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-2880", + "https://pkg.go.dev/vuln/GO-2022-1038", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-2880" + ], + "PublishedDate": "2022-10-14T15:15:18.09Z", + "LastModifiedDate": "2026-06-17T04:42:45.547Z" + }, + { + "VulnerabilityID": "CVE-2022-29804", + "VendorIDs": [ + "GO-2022-0533" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-29804", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2b2cea19b835f75c2db92f4bdcd0732f585e7572fae13bbfdee0e2e50de7e07f", + "Title": "ELSA-2022-17957: ol8addon security update (IMPORTANT)", + "Description": "Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/401595", + "https://go.dev/issue/52476", + "https://go.googlesource.com/go/+/9cd1818a7d019c02fa4898b3e45a323e35033290", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-29804.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-29804", + "https://pkg.go.dev/vuln/GO-2022-0533" + ], + "PublishedDate": "2022-08-10T20:15:34.89Z", + "LastModifiedDate": "2026-06-17T04:40:44.503Z" + }, + { + "VulnerabilityID": "CVE-2022-30580", + "VendorIDs": [ + "GO-2022-0532" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30580", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:29bed90e1a89b36db6cad987e509f02d899a3701f663510ad7f51d326b2536a3", + "Title": "golang: os/exec: Code injection in Cmd.Start", + "Description": "Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either \"..com\" or \"..exe\" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-30580", + "https://go.dev/cl/403759", + "https://go.dev/issue/52574", + "https://go.googlesource.com/go/+/960ffa98ce73ef2c2060c84c7ac28d37a83f345e", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-30580.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30580", + "https://pkg.go.dev/vuln/GO-2022-0532", + "https://www.cve.org/CVERecord?id=CVE-2022-30580" + ], + "PublishedDate": "2022-08-10T20:15:40.227Z", + "LastModifiedDate": "2026-06-17T04:43:53.69Z" + }, + { + "VulnerabilityID": "CVE-2022-30630", + "VendorIDs": [ + "GO-2022-0527" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30630", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b2b98b523fe06e8e72e2d807fd78cf84cfcb10d53e684b59ff85ffbf2585b3f5", + "Title": "golang: io/fs: stack exhaustion in Glob", + "Description": "Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30630", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/315e80d293b684ac2902819e58f618f1b5a14d49%20%281.18%29", + "https://go.dev/cl/417065", + "https://go.dev/issue/53415", + "https://go.googlesource.com/go/+/fa2d41d0ca736f3ad6b200b2a4e134364e9acc59", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30630.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30630", + "https://pkg.go.dev/vuln/GO-2022-0527", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30630" + ], + "PublishedDate": "2022-08-10T20:15:40.977Z", + "LastModifiedDate": "2026-06-17T04:43:58.727Z" + }, + { + "VulnerabilityID": "CVE-2022-30631", + "VendorIDs": [ + "GO-2022-0524" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30631", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:bd30e3f9206400b81406687e05755245f8af09deba21b73d409aacc566b1da4c", + "Title": "golang: compress/gzip: stack exhaustion in Reader.Read", + "Description": "Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30631", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/8e27a8ac4c001c27713810b75925aa3794049c48%20%281.18%29", + "https://go.dev/cl/417067", + "https://go.dev/issue/53168", + "https://go.googlesource.com/go/+/b2b8872c876201eac2d0707276c6999ff3eb185e", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30631.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30631", + "https://pkg.go.dev/vuln/GO-2022-0524", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30631" + ], + "PublishedDate": "2022-08-10T20:15:41.373Z", + "LastModifiedDate": "2026-06-17T04:43:58.893Z" + }, + { + "VulnerabilityID": "CVE-2022-30632", + "VendorIDs": [ + "GO-2022-0522" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30632", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:43214acb14be4a5cc61af1f4f29367f6a6aa635685a2b8fbb6c8130256eae8c3", + "Title": "golang: path/filepath: stack exhaustion in Glob", + "Description": "Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2024:2180", + "https://access.redhat.com/security/cve/CVE-2022-30632", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2024-2180.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/5ebd862b1714dad1544bd10a24c47cdb53ad7f46%20%281.18%29", + "https://go.dev/cl/417066", + "https://go.dev/issue/53416", + "https://go.googlesource.com/go/+/ac68c6c683409f98250d34ad282b9e1b0c9095ef", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30632.html", + "https://linux.oracle.com/errata/ELSA-2024-2180.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30632", + "https://pkg.go.dev/vuln/GO-2022-0522", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30632" + ], + "PublishedDate": "2022-08-10T20:15:41.877Z", + "LastModifiedDate": "2026-06-17T04:43:59.057Z" + }, + { + "VulnerabilityID": "CVE-2022-30633", + "VendorIDs": [ + "GO-2022-0523" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30633", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b80707c361225ad305afdc1c4c7186e3295f50dee0a9ecbbddadf80a9141369e", + "Title": "golang: encoding/xml: stack exhaustion in Unmarshal", + "Description": "Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8057", + "https://access.redhat.com/security/cve/CVE-2022-30633", + "https://bugzilla.redhat.com/2044628", + "https://bugzilla.redhat.com/2045880", + "https://bugzilla.redhat.com/2050648", + "https://bugzilla.redhat.com/2050742", + "https://bugzilla.redhat.com/2050743", + "https://bugzilla.redhat.com/2065290", + "https://bugzilla.redhat.com/2107342", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107376", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2107390", + "https://bugzilla.redhat.com/2107392", + "https://bugzilla.redhat.com/show_bug.cgi?id=2044628", + "https://bugzilla.redhat.com/show_bug.cgi?id=2045880", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050648", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050742", + "https://bugzilla.redhat.com/show_bug.cgi?id=2050743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2055349", + "https://bugzilla.redhat.com/show_bug.cgi?id=2065290", + "https://bugzilla.redhat.com/show_bug.cgi?id=2104367", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107376", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107390", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107392", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23648", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21673", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21698", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21702", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21713", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2022-8057.html", + "https://errata.rockylinux.org/RLSA-2022:8057", + "https://github.com/golang/go/commit/2924ced71d16297320e8ff18829c2038e6ad8d9b%20%281.18%29", + "https://go.dev/cl/417061", + "https://go.dev/issue/53611", + "https://go.googlesource.com/go/+/c4c1993fd2a5b26fe45c09592af6d3388a3b2e08", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30633.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30633", + "https://pkg.go.dev/vuln/GO-2022-0523", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30633" + ], + "PublishedDate": "2022-08-10T20:15:42.21Z", + "LastModifiedDate": "2026-06-17T04:43:59.163Z" + }, + { + "VulnerabilityID": "CVE-2022-30634", + "VendorIDs": [ + "GO-2022-0477" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.11, 1.18.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30634", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:100788d9553764e1e909b3e3c592269e81da01fc3fcd885a8607b9296f52edb8", + "Title": "ELSA-2022-17957: ol8addon security update (IMPORTANT)", + "Description": "Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/402257", + "https://go.dev/issue/52561", + "https://go.googlesource.com/go/+/bb1f4416180511231de6d17a1f2f55c82aafc863", + "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ", + "https://linux.oracle.com/cve/CVE-2022-30634.html", + "https://linux.oracle.com/errata/ELSA-2022-17957.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30634", + "https://pkg.go.dev/vuln/GO-2022-0477" + ], + "PublishedDate": "2022-07-15T20:15:08.597Z", + "LastModifiedDate": "2026-06-17T04:43:59.317Z" + }, + { + "VulnerabilityID": "CVE-2022-30635", + "VendorIDs": [ + "GO-2022-0526" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.12, 1.18.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-30635", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5df9bda0019d7500567d01f9bf6763868775fecb6235fa58ba5c98b90565d0cb", + "Title": "golang: encoding/gob: stack exhaustion in Decoder.Decode", + "Description": "Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-674" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:8250", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-30635", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107342", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107374", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107383", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107386", + "https://bugzilla.redhat.com/show_bug.cgi?id=2107388", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2022:8250", + "https://github.com/golang/go/commit/fb979a50823e5a0575cf6166b3f17a13364cbf81%20%281.18%29", + "https://go.dev/cl/417064", + "https://go.dev/issue/53615", + "https://go.googlesource.com/go/+/6fa37e98ea4382bf881428ee0c150ce591500eb7", + "https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE", + "https://linux.oracle.com/cve/CVE-2022-30635.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-30635", + "https://pkg.go.dev/vuln/GO-2022-0526", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-30635" + ], + "PublishedDate": "2022-08-10T20:15:42.64Z", + "LastModifiedDate": "2026-06-17T04:43:59.43Z" + }, + { + "VulnerabilityID": "CVE-2022-32189", + "VendorIDs": [ + "GO-2022-0537" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.17.13, 1.18.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-32189", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:98b1c0869079742b9feb90ece3b00630d92e5f1b6c51067d097a62f6a3b27c0c", + "Title": "golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service", + "Description": "A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 1, + "rocky": 1, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2022:7950", + "https://access.redhat.com/errata/RHSA-2023:2357", + "https://access.redhat.com/security/cve/CVE-2022-32189", + "https://bugzilla.redhat.com/2107371", + "https://bugzilla.redhat.com/2107374", + "https://bugzilla.redhat.com/2107383", + "https://bugzilla.redhat.com/2107386", + "https://bugzilla.redhat.com/2107388", + "https://bugzilla.redhat.com/2113814", + "https://bugzilla.redhat.com/2124669", + "https://bugzilla.redhat.com/2132868", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/2161274", + "https://bugzilla.redhat.com/show_bug.cgi?id=2059869", + "https://bugzilla.redhat.com/show_bug.cgi?id=2059870", + "https://bugzilla.redhat.com/show_bug.cgi?id=2060061", + "https://bugzilla.redhat.com/show_bug.cgi?id=2062597", + "https://bugzilla.redhat.com/show_bug.cgi?id=2064087", + "https://bugzilla.redhat.com/show_bug.cgi?id=2088459", + "https://bugzilla.redhat.com/show_bug.cgi?id=2105961", + "https://bugzilla.redhat.com/show_bug.cgi?id=2110864", + "https://bugzilla.redhat.com/show_bug.cgi?id=2113814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2118831", + "https://bugzilla.redhat.com/show_bug.cgi?id=2123055", + "https://bugzilla.redhat.com/show_bug.cgi?id=2123210", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32189", + "https://errata.almalinux.org/9/ALSA-2023-2357.html", + "https://errata.rockylinux.org/RLSA-2022:7950", + "https://github.com/golang/go/commit/9240558e4f342fc6e98fec22de17c04b45089349%20%281.18%29", + "https://go.dev/cl/417774", + "https://go.dev/issue/53871", + "https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66", + "https://groups.google.com/g/golang-announce/c/YqYYG87xB10", + "https://groups.google.com/g/golang-nuts/c/DCFSyTGM0wU", + "https://linux.oracle.com/cve/CVE-2022-32189.html", + "https://linux.oracle.com/errata/ELSA-2023-2802.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-32189", + "https://pkg.go.dev/vuln/GO-2022-0537", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://www.cve.org/CVERecord?id=CVE-2022-32189" + ], + "PublishedDate": "2022-08-10T20:15:47.507Z", + "LastModifiedDate": "2026-06-17T04:46:49.81Z" + }, + { + "VulnerabilityID": "CVE-2022-41715", + "VendorIDs": [ + "GO-2022-1039" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.7, 1.19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41715", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7fdb07e23622721aabd64ba4da7529ae6bb3b0825d079b3bed8ac644448ae77a", + "Title": "golang: regexp/syntax: limit memory used by parsing regexps", + "Description": "Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0328", + "https://access.redhat.com/errata/RHSA-2023:2592", + "https://access.redhat.com/security/cve/CVE-2022-41715", + "https://bugzilla.redhat.com/2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2149311", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://errata.almalinux.org/9/ALSA-2023-2592.html", + "https://errata.rockylinux.org/RLSA-2023:0328", + "https://github.com/golang/go/commit/645abfe529dc325e16daa17210640c2907d1c17a%20%28go1.19.2%29", + "https://github.com/golang/go/commit/e9017c2416ad0ef642f5e0c2eab2dbf3cba4d997%20%28go1.18.7%29", + "https://github.com/golang/go/issues/55949", + "https://go.dev/cl/439356", + "https://go.dev/issue/55949", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU", + "https://groups.google.com/g/golang-announce/c/xtuG5faxtaU?pli=1", + "https://linux.oracle.com/cve/CVE-2022-41715.html", + "https://linux.oracle.com/errata/ELSA-2024-3254.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41715", + "https://pkg.go.dev/vuln/GO-2022-1039", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41715" + ], + "PublishedDate": "2022-10-14T15:16:20.78Z", + "LastModifiedDate": "2026-06-17T05:03:41.893Z" + }, + { + "VulnerabilityID": "CVE-2022-41716", + "VendorIDs": [ + "GO-2022-1095" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.8, 1.19.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41716", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b6d0c6fa19b9936dc21c51cde12b3e2f891cf5fad503672d43c6a42d054d3658", + "Title": "Due to unsanitized NUL values, attackers may be able to maliciously se ...", + "Description": "Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string \"A=B\\x00C=D\" sets the variables \"A=B\" and \"C=D\".", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://go.dev/cl/446916", + "https://go.dev/issue/56284", + "https://groups.google.com/g/golang-announce/c/mbHY1UY3BaM/m/hSpmRzk-AgAJ", + "https://linux.oracle.com/cve/CVE-2022-41716.html", + "https://linux.oracle.com/errata/ELSA-2023-18908.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41716", + "https://pkg.go.dev/vuln/GO-2022-1095", + "https://security.netapp.com/advisory/ntap-20230120-0007/" + ], + "PublishedDate": "2022-11-02T16:15:11.15Z", + "LastModifiedDate": "2026-06-17T05:03:41.997Z" + }, + { + "VulnerabilityID": "CVE-2022-41720", + "VendorIDs": [ + "GO-2022-1143" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.18.9, 1.19.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41720", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1846ad792837ca8dd55be2a5b189b36ce15a97ba431788faa1eb7404f23a5f08", + "Title": "golang: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows", + "Description": "On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS(\"C:/tmp\").Open(\"COM1\") opens the COM1 device. Both os.DirFS and http.Dir only provide read-only filesystem access. In addition, on Windows, an os.DirFS for the directory (the root of the current drive) can permit a maliciously crafted path to escape from the drive and access any path on the system. With fix applied, the behavior of os.DirFS(\"\") has changed. Previously, an empty root was treated equivalently to \"/\", so os.DirFS(\"\").Open(\"tmp\") would open the path \"/tmp\". This now returns an error.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-41720", + "https://go.dev/cl/455716", + "https://go.dev/issue/56694", + "https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ", + "https://linux.oracle.com/cve/CVE-2022-41720.html", + "https://linux.oracle.com/errata/ELSA-2023-18908.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41720", + "https://pkg.go.dev/vuln/GO-2022-1143", + "https://www.cve.org/CVERecord?id=CVE-2022-41720" + ], + "PublishedDate": "2022-12-07T17:15:10.293Z", + "LastModifiedDate": "2026-06-17T05:03:42.497Z" + }, + { + "VulnerabilityID": "CVE-2022-41722", + "VendorIDs": [ + "GO-2023-1568" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41722", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:19108904305c59a1d3af08cfc80abe7f3c1ca2ac6a4b653648e71818a55d1c4c", + "Title": "golang: path/filepath: path-filepath filepath.Clean path traversal", + "Description": "A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as \"a/../c:/b\" into the valid path \"c:\\b\". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path \".\\c:\\b\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2022-41722", + "https://go.dev/cl/468123", + "https://go.dev/issue/57274", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41722", + "https://pkg.go.dev/vuln/GO-2023-1568", + "https://www.cve.org/CVERecord?id=CVE-2022-41722" + ], + "PublishedDate": "2023-02-28T18:15:09.887Z", + "LastModifiedDate": "2026-06-17T05:03:42.79Z" + }, + { + "VulnerabilityID": "CVE-2022-41723", + "VendorIDs": [ + "GHSA-vvpx-j8f3-3w6h", + "GO-2023-1571" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41723", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:69e6ffdc12e5100c2bc571cec5b412d88c18993a0a59cde9498756145a36a7ad", + "Title": "golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding", + "Description": "A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41723", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/advisories/GHSA-vvpx-j8f3-3w6h", + "https://go.dev/cl/468135", + "https://go.dev/cl/468295", + "https://go.dev/issue/57855", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41723.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MA5XS5DAOJ5PKKNG5TUXKPQOFHT5VBC/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGW7GE2Z32ZT47UFAQFDRQE33B7Q7LMT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41723", + "https://pkg.go.dev/vuln/GO-2023-1571", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230331-0010/", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://ubuntu.com/security/notices/USN-8089-1", + "https://ubuntu.com/security/notices/USN-8089-2", + "https://ubuntu.com/security/notices/USN-8089-3", + "https://vuln.go.dev/ID/GO-2023-1571.json", + "https://www.couchbase.com/alerts/", + "https://www.cve.org/CVERecord?id=CVE-2022-41723" + ], + "PublishedDate": "2023-02-28T18:15:09.98Z", + "LastModifiedDate": "2026-06-17T05:03:42.9Z" + }, + { + "VulnerabilityID": "CVE-2022-41724", + "VendorIDs": [ + "GO-2023-1570" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41724", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:78b92e75ac266b1048479bf6e0d87eccc5fa32d40b65752f7e245e9c60dae843", + "Title": "golang: crypto/tls: large handshake records may cause panics", + "Description": "Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41724", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://go.dev/cl/468125", + "https://go.dev/issue/58001", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41724.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41724", + "https://pkg.go.dev/vuln/GO-2023-1570", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41724" + ], + "PublishedDate": "2023-02-28T18:15:10.043Z", + "LastModifiedDate": "2026-06-17T05:03:43.11Z" + }, + { + "VulnerabilityID": "CVE-2022-41725", + "VendorIDs": [ + "GO-2023-1569" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.6, 1.20.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-41725", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:35b78438e6204f428b8e0e34fd79913c503a3052addb7e02a339f768fc80adbd", + "Title": "golang: net/http, mime/multipart: denial of service from excessive resource consumption", + "Description": "A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing \"up to maxMemory bytes +10MB (reserved for non-file parts) in memory\". File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did not properly account for all memory consumed by a parsed form, such as map entry overhead, part names, and MIME headers, permitting a maliciously crafted form to consume well over 10MB. In addition, ReadForm contained no limit on the number of disk files created, permitting a relatively small request body to create a large number of disk temporary files. With fix, ReadForm now properly accounts for various forms of memory overhead, and should now stay within its documented limit of 10MB + maxMemory bytes of memory consumption. Users should still be aware that this limit is high and may still be hazardous. In addition, ReadForm now creates at most one on-disk temporary file, combining multiple form parts into a single temporary file. The mime/multipart.File interface type's documentation states, \"If stored on disk, the File's underlying concrete type will be an *os.File.\". This is no longer the case when a form contains more than one file part, due to this coalescing of parts into a single file. The previous behavior of using distinct files for each form part may be reenabled with the environment variable GODEBUG=multipartfiles=distinct. Users should be aware that multipart.ReadForm and the http.Request methods that call it do not limit the amount of disk consumed by temporary files. Callers can limit the size of form data with http.MaxBytesReader.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2022-41725", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/5c55ac9bf1e5f779220294c843526536605f42ab%20%5B1.19%5D", + "https://go.dev/cl/468124", + "https://go.dev/issue/58006", + "https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E", + "https://linux.oracle.com/cve/CVE-2022-41725.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-41725", + "https://pkg.go.dev/vuln/GO-2023-1569", + "https://security.gentoo.org/glsa/202311-09", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2022-41725" + ], + "PublishedDate": "2023-02-28T18:15:10.12Z", + "LastModifiedDate": "2026-06-17T05:03:43.243Z" + }, + { + "VulnerabilityID": "CVE-2023-24534", + "VendorIDs": [ + "GO-2023-1704" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24534", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d381c854437135192d2360229d72bb98a2f858e09b22f21797b89ba97f1c640b", + "Title": "golang: net/http, net/textproto: denial of service from excessive memory allocation", + "Description": "HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more memory than required to hold the parsed headers. An attacker can exploit this behavior to cause an HTTP server to allocate large amounts of memory from a small request, potentially leading to memory exhaustion and a denial of service. With fix, header parsing now correctly allocates only the memory required to hold parsed headers.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24534", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/3991f6c41c7dfd167e889234c0cf1d840475e93c%20%28go1.20.3%29", + "https://github.com/golang/go/commit/d6759e7a059f4208f07aa781402841d7ddaaef96%20%28go1.19.8%29", + "https://go.dev/cl/481994", + "https://go.dev/issue/58975", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24534.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24534", + "https://pkg.go.dev/vuln/GO-2023-1704", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230526-0007/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24534" + ], + "PublishedDate": "2023-04-06T16:15:07.657Z", + "LastModifiedDate": "2026-06-17T05:39:28.893Z" + }, + { + "VulnerabilityID": "CVE-2023-24536", + "VendorIDs": [ + "GO-2023-1705" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24536", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a250e9a7c82653b528d0fe062dba78ac2484df17fbd9228f4b0efbd2237b7fe1", + "Title": "golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption", + "Description": "Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems from several causes: 1. mime/multipart.Reader.ReadForm limits the total memory a parsed multipart form can consume. ReadForm can undercount the amount of memory consumed, leading it to accept larger inputs than intended. 2. Limiting total memory does not account for increased pressure on the garbage collector from large numbers of small allocations in forms with many parts. 3. ReadForm can allocate a large number of short-lived buffers, further increasing pressure on the garbage collector. The combination of these factors can permit an attacker to cause an program that parses multipart forms to consume large amounts of CPU and memory, potentially resulting in a denial of service. This affects programs that use mime/multipart.Reader.ReadForm, as well as form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. With fix, ReadForm now does a better job of estimating the memory consumption of parsed forms, and performs many fewer short-lived allocations. In addition, the fixed mime/multipart.Reader imposes the following limits on the size of parsed forms: 1. Forms parsed with ReadForm may contain no more than 1000 parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxparts=. 2. Form parts parsed with NextPart and NextRawPart may contain no more than 10,000 header fields. In addition, forms parsed with ReadForm may contain no more than 10,000 header fields across all parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxheaders=.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24536", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/7917b5f31204528ea72e0629f0b7d52b35b27538%20%28go.1.19.8%29", + "https://github.com/golang/go/commit/bf8c7c575c8a552d9d79deb29e80854dc88528d0%20%28go1.20.3%29", + "https://go.dev/cl/482075", + "https://go.dev/cl/482076", + "https://go.dev/cl/482077", + "https://go.dev/issue/59153", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24536.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24536", + "https://pkg.go.dev/vuln/GO-2023-1705", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20230526-0007/", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24536" + ], + "PublishedDate": "2023-04-06T16:15:07.71Z", + "LastModifiedDate": "2026-06-17T05:39:29.287Z" + }, + { + "VulnerabilityID": "CVE-2023-24537", + "VendorIDs": [ + "GO-2023-1702" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.8, 1.20.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24537", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:dc77983590f69d12484badf22cd237b05b7b7bfd6a3d2dbcaec6c8c713883f54", + "Title": "golang: go/parser: Infinite loop in parsing", + "Description": "Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24537", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/126a1d02da82f93ede7ce0bd8d3c51ef627f2104%20%28go1.19.8%29", + "https://github.com/golang/go/commit/e7c4b07ecf6b367f1afc9cc48cde963829dd0aab%20%28go1.20.3%29", + "https://github.com/golang/go/issues/59180", + "https://go.dev/cl/482078", + "https://go.dev/issue/59180", + "https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8", + "https://linux.oracle.com/cve/CVE-2023-24537.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24537", + "https://pkg.go.dev/vuln/GO-2023-1702", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241129-0004/", + "https://ubuntu.com/security/notices/USN-6038-1", + "https://ubuntu.com/security/notices/USN-6038-2", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24537" + ], + "PublishedDate": "2023-04-06T16:15:07.753Z", + "LastModifiedDate": "2026-06-17T05:39:29.483Z" + }, + { + "VulnerabilityID": "CVE-2023-24539", + "VendorIDs": [ + "GO-2023-1751" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-24539", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:04133de474997b0a89390a297f2222cb5f82de57b9bd73d2f6598ca9d62a4a9a", + "Title": "golang: html/template: improper sanitization of CSS values", + "Description": "Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-24539", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/090590fdccc8442728aa31601927da1bf2ef1288%20%28go1.20.4%29", + "https://github.com/golang/go/commit/e49282327b05192e46086bf25fd3ac691205fe80%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59720", + "https://go.dev/cl/491615", + "https://go.dev/issue/59720", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-24539.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-24539", + "https://pkg.go.dev/vuln/GO-2023-1751", + "https://security.netapp.com/advisory/ntap-20241129-0005/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-24539" + ], + "PublishedDate": "2023-05-11T16:15:09.6Z", + "LastModifiedDate": "2026-06-17T05:39:29.84Z" + }, + { + "VulnerabilityID": "CVE-2023-29400", + "VendorIDs": [ + "GO-2023-1753" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.9, 1.20.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-29400", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b14919b8b4f1901576b981abf65b3259cc6e17106b43204b95b0cf51635839a8", + "Title": "golang: html/template: improper handling of empty HTML attributes", + "Description": "Templates containing actions in unquoted HTML attributes (e.g. \"attr={{.}}\") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-74", + "CWE-94" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6474", + "https://access.redhat.com/errata/RHSA-2023:6939", + "https://access.redhat.com/security/cve/CVE-2023-29400", + "https://bugzilla.redhat.com/2174485", + "https://bugzilla.redhat.com/2178358", + "https://bugzilla.redhat.com/2178488", + "https://bugzilla.redhat.com/2178492", + "https://bugzilla.redhat.com/2184481", + "https://bugzilla.redhat.com/2184482", + "https://bugzilla.redhat.com/2184483", + "https://bugzilla.redhat.com/2184484", + "https://bugzilla.redhat.com/2196026", + "https://bugzilla.redhat.com/2196027", + "https://bugzilla.redhat.com/2196029", + "https://bugzilla.redhat.com/2222167", + "https://bugzilla.redhat.com/2228689", + "https://bugzilla.redhat.com/show_bug.cgi?id=2163037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2174485", + "https://bugzilla.redhat.com/show_bug.cgi?id=2175721", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178358", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178488", + "https://bugzilla.redhat.com/show_bug.cgi?id=2178492", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2182884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184481", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184482", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184483", + "https://bugzilla.redhat.com/show_bug.cgi?id=2184484", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196026", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196027", + "https://bugzilla.redhat.com/show_bug.cgi?id=2196029", + "https://bugzilla.redhat.com/show_bug.cgi?id=2222167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228689", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3064", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41723", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41724", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41725", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24534", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24536", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24537", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24538", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24539", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24540", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25173", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25809", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27561", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28642", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29400", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29406", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3978", + "https://errata.almalinux.org/9/ALSA-2023-6474.html", + "https://errata.rockylinux.org/RLSA-2023:6939", + "https://github.com/golang/go/commit/337dd75343145b74ed2073d793322eb4103b56ad%20%28go1.20.4%29", + "https://github.com/golang/go/commit/9db0e74f606b8afb28cc71d4b1c8b4ed24cabbf5%20%28go1.19.9%29", + "https://github.com/golang/go/issues/59722", + "https://go.dev/cl/491617", + "https://go.dev/issue/59722", + "https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU", + "https://linux.oracle.com/cve/CVE-2023-29400.html", + "https://linux.oracle.com/errata/ELSA-2023-6939.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-29400", + "https://pkg.go.dev/vuln/GO-2023-1753", + "https://security.netapp.com/advisory/ntap-20241213-0005/", + "https://ubuntu.com/security/notices/USN-6140-1", + "https://www.cve.org/CVERecord?id=CVE-2023-29400" + ], + "PublishedDate": "2023-05-11T16:15:09.85Z", + "LastModifiedDate": "2026-06-17T05:49:57.937Z" + }, + { + "VulnerabilityID": "CVE-2023-29403", + "VendorIDs": [ + "GO-2023-1840" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.19.10, 1.20.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-29403", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c96272dea85bf3a52f9c45cce94eaa105ca55cf903a81687dd4099521004e5a3", + "Title": "golang: runtime: unexpected behavior of setuid/setgid binaries", + "Description": "On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-668" + ], + "VendorSeverity": { + "alma": 4, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 4, + "photon": 3, + "redhat": 3, + "rocky": 4, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:3923", + "https://access.redhat.com/security/cve/CVE-2023-29403", + "https://bugzilla.redhat.com/2216965", + "https://bugzilla.redhat.com/2217562", + "https://bugzilla.redhat.com/2217565", + "https://bugzilla.redhat.com/2217569", + "https://bugzilla.redhat.com/show_bug.cgi?id=2216965", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217562", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217565", + "https://bugzilla.redhat.com/show_bug.cgi?id=2217569", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29402", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29403", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29404", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29405", + "https://errata.almalinux.org/9/ALSA-2023-3923.html", + "https://errata.rockylinux.org/RLSA-2023:3923", + "https://github.com/golang/go/commit/36144ba429ef2650940c72e7a0b932af3612d420%20%28go1.20.5%29", + "https://github.com/golang/go/commit/a7b1cd452ddc69a6606c2f35ac5786dc892e62cb%20%28go1.19.10%29", + "https://github.com/golang/go/issues/60272", + "https://go.dev/cl/501223", + "https://go.dev/issue/60272", + "https://groups.google.com/g/golang-announce/c/q5135a9d924", + "https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJ", + "https://linux.oracle.com/cve/CVE-2023-29403.html", + "https://linux.oracle.com/errata/ELSA-2023-3923.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZ2O6YCO2IZMZJELQGZYR2WAUNEDLYV6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XBS3IIK6ADV24C5ULQU55QLT2UE762ZX/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-29403", + "https://pkg.go.dev/vuln/GO-2023-1840", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20241220-0009/", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cve.org/CVERecord?id=CVE-2023-29403" + ], + "PublishedDate": "2023-06-08T21:15:16.927Z", + "LastModifiedDate": "2026-06-17T05:49:58.43Z" + }, + { + "VulnerabilityID": "CVE-2023-39325", + "VendorIDs": [ + "GHSA-4374-p667-p6c8", + "GO-2023-2102" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.10, 1.21.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-39325", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6fc450df2db14123d0d1a6b7f6b9191d075eb0c263c2eeaa1dca829010d538a3", + "Title": "golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)", + "Description": "A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "bottlerocket": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 3, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39325", + "https://access.redhat.com/errata/RHSA-2023:6077", + "https://access.redhat.com/security/cve/CVE-2023-39325", + "https://access.redhat.com/security/cve/CVE-2023-44487", + "https://bugzilla.redhat.com/2242803", + "https://bugzilla.redhat.com/2243296", + "https://bugzilla.redhat.com/show_bug.cgi?id=2242803", + "https://bugzilla.redhat.com/show_bug.cgi?id=2243296", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39325", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44487", + "https://errata.almalinux.org/9/ALSA-2023-6077.html", + "https://errata.rockylinux.org/RLSA-2023:6077", + "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-48vh-q3rp-4grw", + "https://github.com/golang/go/commit/24ae2d927285c697440fdde3ad7f26028354bcf3%20%5Bgolang-%201.21%5D", + "https://github.com/golang/go/commit/e175f27f58aa7b9cd4d79607ae65d2cd5baaee68%20%5Bgolang-1.20%5D", + "https://github.com/golang/go/issues/63417", + "https://go.dev/cl/534215", + "https://go.dev/cl/534235", + "https://go.dev/issue/63417", + "https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ", + "https://linux.oracle.com/cve/CVE-2023-39325.html", + "https://linux.oracle.com/errata/ELSA-2023-5867.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3OVW5V2DM5K5IC3H7O42YDUGNJ74J35O/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3SZN67IL7HMGMNAVLOTIXLIHUDXZK4LH/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WJ4QVX2AMUJ2F2S27POOAHRC4K3CHU4/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5RSKA2II6QTD4YUKUNDVJQSRYSFC4VFR/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVZDNSMVDAQJ64LJC5I5U5LDM5753647/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2BBIDR2ZMB3X5BC7SR4SLQMHRMVPY6L/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECRC75BQJP6FJN2L7KCKYZW4DSBD7QSD/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FTMJ3NJIDAZFWJQQSP3L22MUFJ3UP2PT/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSY7SXFFTPZFWDM6XELSDSHZLVW3AHK7/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HZQIELEIRSZUYTFFH5KTH2YJ4IIQG2KE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPWCNYB5PQ5PCVZ4NJT6G56ZYFZ5QBU6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5E5JSJBZLYXOTZWXHJKRVCIXIHVWKJ6/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZQYOOKHQDQ57LV2IAG6NRFOVXKHJJ3Z/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NG7IMPL55MVWU3LCI4JQJT3K2U5CHDV7/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ODBY7RVMGZCBSTWF2OZGIZS57FNFUL67/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXGWPQOJ3JNDW2XIYKIVJ7N7QUIFNM2Q/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PJCUNGIQDUMZ4Z6HWVYIMR66A35F5S74/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QF5QSYAOPDOWLY6DUHID56Q4HQFYB45I/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXOU2JZUBEBP7GBKAYIJRPRBZSJCD7ST/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3UETKPUB3V5JS5TLZOF3SMTGT5K5APS/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULQQONMSCQSH5Z5OWFFQHCGEZ3NL4DRJ/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTT7DG3QOF5ZNJLUGHDNLRUIN6OWZARP/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2LZSWTV4NV4SNQARNXG5T6LRHP26EW2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WCNCBYKZXLDFGAJUB7ZP5VLC3YTHJNVH/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XTNLSL44Y5FB6JWADSZH6DCV4JJAAEQY/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJWHBLVZDM5KQSDFRBFRKU5KSSOLIRQ4/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRKEXKANQ7BKJW2YTAMP625LJUJZLJ4P/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZSVEMQV5ROY5YW5QE3I57HT3ITWG5GCV/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-39325", + "https://pkg.go.dev/vuln/GO-2023-2102", + "https://security.gentoo.org/glsa/202311-09", + "https://security.netapp.com/advisory/ntap-20231110-0008/", + "https://ubuntu.com/security/notices/USN-6574-1", + "https://ubuntu.com/security/notices/USN-7061-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487", + "https://www.cve.org/CVERecord?id=CVE-2023-39325" + ], + "PublishedDate": "2023-10-11T22:15:09.88Z", + "LastModifiedDate": "2026-06-17T06:12:02.173Z" + }, + { + "VulnerabilityID": "CVE-2023-45283", + "VendorIDs": [ + "GO-2023-2185" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.11, 1.21.4, 1.20.12, 1.21.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:fa78e46ea533fea768b25e77a41e9cc3aba110bf8d6df0bf649f4af9f9ba97d6", + "Title": "The filepath package does not recognize paths with a \\??\\ prefix as sp ...", + "Description": "The filepath package does not recognize paths with a \\??\\ prefix as special. On Windows, a path beginning with \\??\\ is a Root Local Device path equivalent to a path beginning with \\\\?\\. Paths with a \\??\\ prefix may be used to access arbitrary locations on the system. For example, the path \\??\\c:\\x is equivalent to the more common path c:\\x. Before fix, Clean could convert a rooted path such as \\a\\..\\??\\b into the root local device path \\??\\b. Clean will now convert this to .\\??\\b. Similarly, Join(\\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \\??\\b. Join will now convert this to \\.\\??\\b. In addition, with fix, IsAbs now correctly reports paths beginning with \\??\\ as absolute, and VolumeName correctly reports the \\??\\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \\?, resulting in filepath.Clean(\\?\\c:) returning \\?\\c: rather than \\?\\c:\\ (among other effects). The previous behavior has been restored.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "amazon": 2, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "photon": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2023/12/05/2", + "https://go.dev/cl/540277", + "https://go.dev/cl/541175", + "https://go.dev/issue/63713", + "https://go.dev/issue/64028", + "https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY", + "https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45283", + "https://pkg.go.dev/vuln/GO-2023-2185", + "https://security.netapp.com/advisory/ntap-20231214-0008/" + ], + "PublishedDate": "2023-11-09T17:15:08.757Z", + "LastModifiedDate": "2026-06-17T06:28:34.863Z" + }, + { + "VulnerabilityID": "CVE-2023-45287", + "VendorIDs": [ + "GO-2023-2375" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.20.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45287", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:67ddc2362eea00e0c3dab439f8ad7648ed09bf992fb431c7c3e1afe44c60755c", + "Title": "golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.", + "Description": "Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-203" + ], + "VendorSeverity": { + "alma": 2, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:2272", + "https://access.redhat.com/errata/RHSA-2024:2988", + "https://access.redhat.com/security/cve/CVE-2023-45287", + "https://bugzilla.redhat.com/2253193", + "https://bugzilla.redhat.com/2253330", + "https://bugzilla.redhat.com/show_bug.cgi?id=1983596", + "https://bugzilla.redhat.com/show_bug.cgi?id=1989575", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132867", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132868", + "https://bugzilla.redhat.com/show_bug.cgi?id=2132872", + "https://bugzilla.redhat.com/show_bug.cgi?id=2228743", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237773", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237776", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237777", + "https://bugzilla.redhat.com/show_bug.cgi?id=2237778", + "https://bugzilla.redhat.com/show_bug.cgi?id=2244340", + "https://bugzilla.redhat.com/show_bug.cgi?id=2246840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2253193", + "https://bugzilla.redhat.com/show_bug.cgi?id=2253330", + "https://bugzilla.redhat.com/show_bug.cgi?id=2254210", + "https://bugzilla.redhat.com/show_bug.cgi?id=2262272", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25091", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33198", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29409", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39318", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39319", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39326", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45287", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23650", + "https://errata.almalinux.org/9/ALSA-2024-2272.html", + "https://errata.rockylinux.org/RLSA-2024:2988", + "https://go.dev/cl/326012/26", + "https://go.dev/issue/20654", + "https://groups.google.com/g/golang-announce/c/QMK8IQALDvA", + "https://linux.oracle.com/cve/CVE-2023-45287.html", + "https://linux.oracle.com/errata/ELSA-2024-2988.html", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45287", + "https://people.redhat.com/~hkario/marvin/", + "https://pkg.go.dev/vuln/GO-2023-2375", + "https://security.netapp.com/advisory/ntap-20240112-0005/", + "https://www.cve.org/CVERecord?id=CVE-2023-45287" + ], + "PublishedDate": "2023-12-05T17:15:08.57Z", + "LastModifiedDate": "2026-06-17T06:28:35.46Z" + }, + { + "VulnerabilityID": "CVE-2023-45288", + "VendorIDs": [ + "GHSA-4v7x-pqxf-cx7m", + "GO-2024-2687" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.21.9, 1.22.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-45288", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5fb5dc4b793c754bd073d8b27dba2c4a438c81e2936cb0cf0c0bab065b63999c", + "Title": "golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS", + "Description": "An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "bottlerocket": 2, + "cbl-mariner": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288", + "http://www.openwall.com/lists/oss-security/2024/04/03/16", + "http://www.openwall.com/lists/oss-security/2024/04/05/4", + "https://access.redhat.com/errata/RHSA-2024:2724", + "https://access.redhat.com/security/cve/CVE-2023-45288", + "https://bugzilla.redhat.com/2268017", + "https://bugzilla.redhat.com/2268018", + "https://bugzilla.redhat.com/2268019", + "https://bugzilla.redhat.com/2268273", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268017", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268018", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268019", + "https://bugzilla.redhat.com/show_bug.cgi?id=2268273", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45288", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45289", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45290", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24783", + "https://errata.almalinux.org/9/ALSA-2024-2724.html", + "https://errata.rockylinux.org/RLSA-2024:2724", + "https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-c9wf-j9h6-m2r9", + "https://go.dev/cl/576155", + "https://go.dev/issue/65051", + "https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M", + "https://kb.cert.org/vuls/id/421644", + "https://linux.oracle.com/cve/CVE-2023-45288.html", + "https://linux.oracle.com/errata/ELSA-2024-3346.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRYFHIQ6XRKRYBI2F5UESH67BJBQXUPT/", + "https://nowotarski.info/http2-continuation-flood/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-45288", + "https://pkg.go.dev/vuln/GO-2024-2687", + "https://security.netapp.com/advisory/ntap-20240419-0009/", + "https://ubuntu.com/security/notices/USN-6886-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2023-45288", + "https://www.kb.cert.org/vuls/id/421644" + ], + "PublishedDate": "2024-04-04T21:15:16.113Z", + "LastModifiedDate": "2026-06-17T06:28:35.58Z" + }, + { + "VulnerabilityID": "CVE-2024-34156", + "VendorIDs": [ + "GO-2024-3106" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.22.7, 1.23.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-34156", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8418b64554137b265d245db04e9b737d0356e0356bc4eeae8749621cdcd244e4", + "Title": "encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion", + "Description": "Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.", + "Severity": "HIGH", + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:3773", + "https://access.redhat.com/security/cve/CVE-2024-34156", + "https://bugzilla.redhat.com/2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2310528", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341750", + "https://bugzilla.redhat.com/show_bug.cgi?id=2341751", + "https://bugzilla.redhat.com/show_bug.cgi?id=2344219", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45336", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45341", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22866", + "https://errata.almalinux.org/9/ALSA-2025-3773.html", + "https://errata.rockylinux.org/RLSA-2025:3773", + "https://github.com/golang/go/commit/2092294f2b097c5828f4eace6c98a322c1510b01%20%28go1.22.7%29", + "https://github.com/golang/go/commit/fa8ff1a46deb6c816304441ec6740ec112e19012%20%28go1.23.1%29", + "https://go.dev/cl/611239", + "https://go.dev/issue/69139", + "https://groups.google.com/g/golang-announce/c/K-cEzDeCtpc", + "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk", + "https://linux.oracle.com/cve/CVE-2024-34156.html", + "https://linux.oracle.com/errata/ELSA-2025-3773.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-34156", + "https://pkg.go.dev/vuln/GO-2024-3106", + "https://security.netapp.com/advisory/ntap-20240926-0004/", + "https://ubuntu.com/security/notices/USN-7081-1", + "https://ubuntu.com/security/notices/USN-7109-1", + "https://ubuntu.com/security/notices/USN-7111-1", + "https://www.cve.org/CVERecord?id=CVE-2024-34156" + ], + "PublishedDate": "2024-09-06T21:15:12.02Z", + "LastModifiedDate": "2026-06-17T07:33:00.72Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3854418b76f2679250bd280fcb421e8507a7e2b6b1e9cb091cc8c4d1d12c0b25", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-08-14T13:17:15.67Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6860f836490dfde258e0042abe04f456c5f6faf1b44123625014a691aa7b438d", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:964d65953763b7944427332d3ebe957a2ac081bcfbcb7d1620a35842e9d0d421", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-08-14T13:17:46.517Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ea25d145e74d3835c20fadbb93759eeb3c20fe84c3e418d0a1d3e7348c3bf087", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-08-14T13:17:49.537Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:14d54b97c934e5a393d3a3ba132ef098bd5fcd1f680aad75e998b8b916f65ffb", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-08-14T13:17:52.587Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:712b5f7b0fbb583e7048b498bdc3ccf0e4a91c1950ca2fc5b909380074047204", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:49838", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-49838.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4a6eeeea39cbfcf529ea93857f5005c63946f465f0c3acb439e6d89e427ba2b5", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-33722.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-08-14T13:17:54.66Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5d29eeb834bae27a6cbf72a10a3ec40d89e4330ee0691243be8f504a4d1fc2e4", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:39319", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-39573.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-08-14T13:18:12Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:994942bc9f00288617f1254db485c553ed859d52da3ebf386b9a70905a68203d", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-08-13T13:18:25.52Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9eb6d4b7fdb9f31a365b8c2cefec7af31df43fc9512e1234ee38afe50fd2ac46", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-08-14T16:16:55.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:db830f6ee10c12e1bd411fcf63432c8d5a86c66f84b7a17a297c9fd6fe47a7b3", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-08-14T13:18:23.657Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:617726814b68f4ea99d6d321d4263dac75b89b2b0354b12475e2549c1c825557", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:37435", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-08-14T13:18:24.667Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:027edcbc77bbc7c26cf7c6520b04f9e10462ceca56ee970298822793920d3f6d", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0d71bde7eb6027a01b7a22e80954366c631a9f423342bd3a766032ffaa10fe3a", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:045d4fee82071195e51fdb67c059c21990728b2afee8841208f807fbb8f296ce", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-08-14T13:18:47.497Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:51443548fce7d72c5c2e26fb9989784f2c9bf11f85df1284eb8354bf903c96f9", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d99ca1040872967413ade7f6007da4ae2d07dba76f615c1044d726abb181940d", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-08-14T16:16:57.21Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:23f8882e459d2277e5505cdfc314eb0d7556f9d4892bf5182857c3289c1018a7", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-08-14T16:16:57.367Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:587f5019d75f3f61420ea0e8009d1964ba1815dfa4c72fb328093866c905f815", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-08-14T16:16:57.523Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4b0c7828aae8449770bcb24379e73036b1e3d075e8055bab398c4db7b01ed5a0", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-08-14T17:19:13.91Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.17", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.17", + "UID": "fdbfe62aba500b23" + }, + "InstalledVersion": "v1.17", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6c71cbb2db6d8e6ad0f39229cb37c1fe0687d03d2894b51619c30fdcc2ba0452", + "DiffID": "sha256:3e67d66085781ea424b02a31c90364ade97a6d50977ad19eaaff3812c37ea3bd" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:35e5e34c7b3002ac9c281eb40052a17b1b4e6a01fbf7e82cfc16285171207ccf", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-08-14T16:16:57.717Z" + } + ], + "vulnerability_count": 301 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 301 + } +} diff --git a/bfx/ipyrad/trivy-scan-results.json b/bfx/ipyrad/trivy-scan-results.json new file mode 100644 index 00000000..822a0682 --- /dev/null +++ b/bfx/ipyrad/trivy-scan-results.json @@ -0,0 +1,2729 @@ +{ + "tool": "ipyrad", + "scan_timestamp": "2026-08-16T17:08:50Z", + "workflow_run_id": "31960542324", + "versions": { + "0.9.108": { + "image": "ghcr.io/bundlecore/products/bfx/ipyrad:0.9.108", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-44727", + "VendorIDs": [ + "GHSA-fcw5-x6j4-ccmp" + ], + "PkgName": "jupyter_server", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_server-2.17.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-server@2.17.0", + "UID": "c8eb9dcbc228f62a" + }, + "InstalledVersion": "2.17.0", + "FixedVersion": "2.20.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44727", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:dcc384390d920f80aa4c8a0892df68909189053a51caf9cf586618be57016c64", + "Title": "jupyter-server: Jupyter Server: Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers", + "Description": "Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE. This vulnerability is fixed in 2.20.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-79", + "CWE-1021" + ], + "VendorSeverity": { + "ghsa": 4, + "nvd": 2, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H", + "V3Score": 5.4, + "V40Score": 9.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 5.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-44727", + "https://bugzilla.redhat.com/show_bug.cgi?id=2491516", + "https://github.com/advisories/GHSA-fcw5-x6j4-ccmp", + "https://github.com/jupyter-server/jupyter_server", + "https://github.com/jupyter-server/jupyter_server/commit/6cbee8d65e71abac851c4492fea987ad080580bd", + "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmp", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-366.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44727", + "https://pypi.org/project/jupyter-server", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44727.json", + "https://www.cve.org/CVERecord?id=CVE-2026-44727" + ], + "PublishedDate": "2026-06-22T21:16:24.26Z", + "LastModifiedDate": "2026-07-22T12:18:06.24Z" + }, + { + "VulnerabilityID": "CVE-2026-35397", + "VendorIDs": [ + "GHSA-5789-5fc7-67v3" + ], + "PkgName": "jupyter_server", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_server-2.17.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-server@2.17.0", + "UID": "c8eb9dcbc228f62a" + }, + "InstalledVersion": "2.17.0", + "FixedVersion": "2.18.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-35397", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:7563ea3114bf04ea8a2b4b68d264ae62def0c968f3a571604ed88fac70724587", + "Title": "jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability", + "Description": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named \"test\", the API permits access to a sibling directory named \"testtest\" through a crafted request to the /api/contents endpoint using encoded path components. An attacker can read, write, and delete files in affected sibling directories. Multi-tenant deployments using predictable naming schemes are particularly at risk, as a user with a directory named \"user1\" could access directories for user10 through user19 and beyond. A user who can choose a single-character folder name could gain access to a significant number of sibling directories. \n\nVersion 2.18.0 contains a fix. As a workaround, ensure folder names do not share a common prefix with any sibling directory.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N", + "V3Score": 7.1, + "V40Score": 7.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-35397", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466858", + "https://github.com/jupyter-server/jupyter_server", + "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-68.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-35397", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35397.json", + "https://www.cve.org/CVERecord?id=CVE-2026-35397" + ], + "PublishedDate": "2026-05-05T20:16:38.223Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-40110", + "VendorIDs": [ + "GHSA-24qx-w28j-9m6p" + ], + "PkgName": "jupyter_server", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_server-2.17.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-server@2.17.0", + "UID": "c8eb9dcbc228f62a" + }, + "InstalledVersion": "2.17.0", + "FixedVersion": "2.18.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40110", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:581a1112091f47bd2bc310d749f9f35b623463160d7882a023bcc9a95ad1a8a4", + "Title": "jupyter-server: Jupyter Server: Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation", + "Description": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-777", + "CWE-625" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L", + "V40Score": 7.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 7.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-40110", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466912", + "https://github.com/jupyter-server/jupyter_server", + "https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea", + "https://github.com/jupyter-server/jupyter_server/commit/49b34392feaa97735b3b777e3baf8f22f2a14ed8", + "https://github.com/jupyter-server/jupyter_server/pull/603", + "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-2187.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40110", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40110.json", + "https://www.cve.org/CVERecord?id=CVE-2026-40110" + ], + "PublishedDate": "2026-05-05T22:16:00.663Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-40934", + "VendorIDs": [ + "GHSA-5mrq-x3x5-8v8f" + ], + "PkgName": "jupyter_server", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyter_server-2.17.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyter-server@2.17.0", + "UID": "c8eb9dcbc228f62a" + }, + "InstalledVersion": "2.17.0", + "FixedVersion": "2.18.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40934", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:d5e83184f906452f9d6f6a2b4af97ac3de00d42c76dc938a9ca5084992256926", + "Title": "jupyter-server: Jupyter Server: Authentication bypass due to unrotated cookie secret", + "Description": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-613" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 2, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", + "V3Score": 6.8, + "V40Score": 7.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-40934", + "https://github.com/jupyter-server/jupyter_server", + "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-69.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40934", + "https://www.cve.org/CVERecord?id=CVE-2026-40934" + ], + "PublishedDate": "2026-05-05T22:16:00.82Z", + "LastModifiedDate": "2026-07-25T11:10:00.1Z" + }, + { + "VulnerabilityID": "CVE-2026-40171", + "VendorIDs": [ + "GHSA-rch3-82jr-f9w9" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.5.4", + "UID": "352eb861a79a7efa" + }, + "InstalledVersion": "4.5.4", + "FixedVersion": "4.5.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40171", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c3df9f036297284857c81d641ec853f8d2e0ee9a9c3697584653a5a8a374f762", + "Title": "Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting", + "Description": "In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.\n\nAn attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's authentication token and complete takeover of the Jupyter session through the REST API, including reading files, creating or modifying files, accessing kernels to execute arbitrary code, and creating terminals for shell access. This issue has been fixed in Notebook 7.5.6, JupyterLab 4.5.7, @jupyter-notebook/help-extension 7.5.6, and @jupyterlab/help-extension 4.5.7. As a workaround, disable the affected help extensions or set allowCommandLinker to false in the sanitizer configuration.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.4 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-40171", + "https://github.com/jupyter/notebook", + "https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9", + "https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-output-and-files", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40171", + "https://www.cve.org/CVERecord?id=CVE-2026-40171" + ], + "PublishedDate": "2026-05-06T20:16:31.857Z", + "LastModifiedDate": "2026-06-17T10:44:48.747Z" + }, + { + "VulnerabilityID": "CVE-2026-42266", + "VendorIDs": [ + "GHSA-37w4-hwhx-4rc4" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.5.4", + "UID": "352eb861a79a7efa" + }, + "InstalledVersion": "4.5.4", + "FixedVersion": "4.5.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42266", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:20987b4aada2f628de1294a78086d24c536afb0dd82f13a364e52a4cd173b73b", + "Title": "jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list", + "Description": "JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-88", + "CWE-602" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-42266", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477072", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4", + "https://github.com/pypa/advisory-database/tree/main/vulns/jupyterlab/PYSEC-2026-164.yaml", + "https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html", + "https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42266", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42266.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42266" + ], + "PublishedDate": "2026-05-13T16:16:47.017Z", + "LastModifiedDate": "2026-07-22T12:17:54.223Z" + }, + { + "VulnerabilityID": "CVE-2026-42557", + "VendorIDs": [ + "GHSA-mqcg-5x36-vfcg" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.5.4", + "UID": "352eb861a79a7efa" + }, + "InstalledVersion": "4.5.4", + "FixedVersion": "4.5.7", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42557", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:699b6ca39057c1d54a994586db701720eb5a39225607603e6451da262dde8a4e", + "Title": "jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.7, + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 9.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-42557", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477086", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg", + "https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-files", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42557", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42557.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42557" + ], + "PublishedDate": "2026-05-13T16:16:48.167Z", + "LastModifiedDate": "2026-07-22T12:17:56.103Z" + }, + { + "VulnerabilityID": "CVE-2026-73415", + "VendorIDs": [ + "GHSA-gx64-gj6p-pc4c" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.5.4", + "UID": "352eb861a79a7efa" + }, + "InstalledVersion": "4.5.4", + "FixedVersion": "4.6.2, 4.5.10", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-73415", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9e9b53ff1916399e33e010763fd0efb13c6d7a0151a17253a88f33ab418bc3e1", + "Title": "jupyterlab: JupyterLab: Arbitrary code execution via malicious image in image viewer", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early, allowing the image to retain an executable same-origin context when it is opened through the image viewer and then opened in a new browser tab. The resulting cross-site scripting can be used to execute arbitrary code on the JupyterLab server. This issue is fixed in versions 4.5.10 and 4.6.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N", + "V40Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-73415", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/commit/9365f020baec5221deaf11535ed554c06637c999", + "https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c", + "https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432", + "https://github.com/jupyterlab/jupyterlab/pull/19184", + "https://github.com/jupyterlab/jupyterlab/pull/19185", + "https://github.com/jupyterlab/jupyterlab/pull/19186", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.7.0a1", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c", + "https://nvd.nist.gov/vuln/detail/CVE-2026-73415", + "https://www.cve.org/CVERecord?id=CVE-2026-73415" + ], + "PublishedDate": "2026-08-12T20:17:56.66Z", + "LastModifiedDate": "2026-08-12T21:17:40.77Z" + }, + { + "VulnerabilityID": "CVE-2026-73417", + "VendorIDs": [ + "GHSA-pppj-hq3g-57pj" + ], + "PkgName": "jupyterlab", + "PkgPath": "usr/local/lib/python3.12/site-packages/jupyterlab-4.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/jupyterlab@4.5.4", + "UID": "352eb861a79a7efa" + }, + "InstalledVersion": "4.5.4", + "FixedVersion": "4.6.2, 4.5.10", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-73417", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:0bf25edb505709e940ac44175fb91a88507d4c4eb8ab8d97f9f074bcc1f3c118", + "Title": "jupyterlab: JupyterLab: Cross-site scripting (XSS) allows arbitrary code execution", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an overrides.json file using the Import button in the Settings Editor. In packages/notebook-extension/schema/tracker.json and packages/notebook-extension/src/index.ts, the sideBySideLeftMarginOverride and sideBySideRightMarginOverride settings are not properly validated before being inserted into style content, allowing a crafted settings file to contain instructions that execute as code instead of only changing display preferences. A user can import the malicious file, or an attacker with access to a shared settings location can plant an overrides.json that is applied automatically. The embedded code runs with the affected user's access and can read or modify notebooks and files and run code through the notebook server, including on a connected kernel. This issue is fixed in versions 4.5.10 and 4.6.2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79", + "CWE-116" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:L", + "V40Score": 8.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L", + "V3Score": 8.3 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-73417", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/commit/9365f020baec5221deaf11535ed554c06637c999", + "https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c", + "https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432", + "https://github.com/jupyterlab/jupyterlab/pull/19184", + "https://github.com/jupyterlab/jupyterlab/pull/19185", + "https://github.com/jupyterlab/jupyterlab/pull/19186", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2", + "https://github.com/jupyterlab/jupyterlab/releases/tag/v4.7.0a1", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-73417", + "https://www.cve.org/CVERecord?id=CVE-2026-73417" + ], + "PublishedDate": "2026-08-13T22:17:26.133Z", + "LastModifiedDate": "2026-08-14T17:20:32.837Z" + }, + { + "VulnerabilityID": "CVE-2026-33079", + "VendorIDs": [ + "GHSA-8mp2-v27r-99xp" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.2.0", + "UID": "733ee00a2508ff38" + }, + "InstalledVersion": "3.2.0", + "FixedVersion": "3.2.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33079", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:1dda2c5c237ac602dad612c9a153d72b1a7916d942fde6c167a321f6ba744ee1", + "Title": "mistune: Mistune: Regular Expression Denial of Service (ReDoS) via crafted Markdown input", + "Description": "In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles contains overlapping alternatives that can trigger catastrophic backtracking. In both the double-quoted and single-quoted branches, a backslash followed by punctuation can be matched either as an escaped punctuation sequence or as two ordinary characters, creating an ambiguous pattern inside a repeated group. If an attacker supplies Markdown containing repeated ! sequences with no closing quote, the regex engine explores an exponential number of backtracking paths. This is reachable through normal Markdown parsing of inline links and block link reference definitions. A small crafted input can therefore cause significant CPU consumption and make applications using Mistune unresponsive.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-33079", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467298", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/blob/df23edd60b43b639d2e6760ef9dd3d618aa11c21/src/mistune/helpers.py#L20-L25", + "https://github.com/lepture/mistune/security/advisories/GHSA-8mp2-v27r-99xp", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33079", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33079.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33079" + ], + "PublishedDate": "2026-05-06T18:16:03.097Z", + "LastModifiedDate": "2026-07-22T12:17:35.443Z" + }, + { + "VulnerabilityID": "CVE-2026-49851", + "VendorIDs": [ + "GHSA-qcq2-496w-v96p" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.2.0", + "UID": "733ee00a2508ff38" + }, + "InstalledVersion": "3.2.0", + "FixedVersion": "3.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49851", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:0b138d05f9a7b61aab04ab4fb4d1db629b9bf62dc1c8dde7f0af5f4e37ed2bb2", + "Title": "Mistune: Mistune: Denial of Service via crafted Markdown input", + "Description": "Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repeatedly scans the input using a regex search inside a loop. Each iteration re-scans a large portion of the remaining string, resulting in quadratic-time behavior. An attacker-controlled Markdown input can therefore trigger excessive CPU usage with a very small payload. This vulnerability is fixed in 3.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-407", + "CWE-770", + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-49851", + "https://bugzilla.redhat.com/show_bug.cgi?id=2492304", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p", + "https://nvd.nist.gov/vuln/detail/CVE-2026-49851", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49851.json", + "https://www.cve.org/CVERecord?id=CVE-2026-49851" + ], + "PublishedDate": "2026-06-24T18:17:18.937Z", + "LastModifiedDate": "2026-07-15T02:22:36.243Z" + }, + { + "VulnerabilityID": "CVE-2026-59922", + "VendorIDs": [ + "GHSA-c8j7-8cv4-2xmq" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.2.0", + "UID": "733ee00a2508ff38" + }, + "InstalledVersion": "3.2.0", + "FixedVersion": "3.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59922", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c306bfcaf0b3ecab3ec6a57c8a6c0fbfe20a003ea099eac82855606a2f90565f", + "Title": "mistune: Mistune: Denial of Service via crafted input", + "Description": "Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start position, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407", + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59922", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7", + "https://github.com/lepture/mistune/releases/tag/v3.3.0", + "https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq", + "https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2210.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59922", + "https://www.cve.org/CVERecord?id=CVE-2026-59922" + ], + "PublishedDate": "2026-07-08T17:17:27.77Z", + "LastModifiedDate": "2026-07-09T19:36:00.01Z" + }, + { + "VulnerabilityID": "CVE-2026-59925", + "VendorIDs": [ + "GHSA-4j32-57v6-6g45" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.2.0", + "UID": "733ee00a2508ff38" + }, + "InstalledVersion": "3.2.0", + "FixedVersion": "3.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59925", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3959ec7c3bf6bab54b863f5e4199f5ecbda9f596fa09eb61f0c5810fec8f642b", + "Title": "mistune: Mistune: Denial of Service via crafted Markdown input", + "Description": "Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential opening run, allowing denial of service in default Mistune parsing. This issue is fixed in version 3.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407", + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59925", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f", + "https://github.com/lepture/mistune/releases/tag/v3.3.0", + "https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45", + "https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2213.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59925", + "https://www.cve.org/CVERecord?id=CVE-2026-59925" + ], + "PublishedDate": "2026-07-08T17:17:28.183Z", + "LastModifiedDate": "2026-07-09T19:39:58.87Z" + }, + { + "VulnerabilityID": "CVE-2026-59928", + "VendorIDs": [ + "GHSA-ffq3-xpv3-j92q" + ], + "PkgName": "mistune", + "PkgPath": "usr/local/lib/python3.12/site-packages/mistune-3.2.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/mistune@3.2.0", + "UID": "733ee00a2508ff38" + }, + "InstalledVersion": "3.2.0", + "FixedVersion": "3.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59928", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:56604a33e95e7c21b84bb01929ea91b4de8c2444f98af45fda77165931bd9f49", + "Title": "mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitions", + "Description": "Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407", + "CWE-1333" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "photon": 3, + "redhat": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59928", + "https://github.com/lepture/mistune", + "https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69", + "https://github.com/lepture/mistune/releases/tag/v3.3.0", + "https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q", + "https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2216.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59928", + "https://www.cve.org/CVERecord?id=CVE-2026-59928" + ], + "PublishedDate": "2026-07-08T17:17:28.6Z", + "LastModifiedDate": "2026-07-09T19:29:34.207Z" + }, + { + "VulnerabilityID": "CVE-2026-40171", + "VendorIDs": [ + "GHSA-rch3-82jr-f9w9" + ], + "PkgName": "notebook", + "PkgPath": "usr/local/lib/python3.12/site-packages/notebook-7.5.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/notebook@7.5.3", + "UID": "46a31d4195763fb0" + }, + "InstalledVersion": "7.5.3", + "FixedVersion": "7.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40171", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c3df9f036297284857c81d641ec853f8d2e0ee9a9c3697584653a5a8a374f762", + "Title": "Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting", + "Description": "In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.\n\nAn attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's authentication token and complete takeover of the Jupyter session through the REST API, including reading files, creating or modifying files, accessing kernels to execute arbitrary code, and creating terminals for shell access. This issue has been fixed in Notebook 7.5.6, JupyterLab 4.5.7, @jupyter-notebook/help-extension 7.5.6, and @jupyterlab/help-extension 4.5.7. As a workaround, disable the affected help extensions or set allowCommandLinker to false in the sanitizer configuration.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.4 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-40171", + "https://github.com/jupyter/notebook", + "https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9", + "https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-output-and-files", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40171", + "https://www.cve.org/CVERecord?id=CVE-2026-40171" + ], + "PublishedDate": "2026-05-06T20:16:31.857Z", + "LastModifiedDate": "2026-06-17T10:44:48.747Z" + }, + { + "VulnerabilityID": "CVE-2026-42557", + "VendorIDs": [ + "GHSA-mqcg-5x36-vfcg" + ], + "PkgName": "notebook", + "PkgPath": "usr/local/lib/python3.12/site-packages/notebook-7.5.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/notebook@7.5.3", + "UID": "46a31d4195763fb0" + }, + "InstalledVersion": "7.5.3", + "FixedVersion": "7.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42557", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:699b6ca39057c1d54a994586db701720eb5a39225607603e6451da262dde8a4e", + "Title": "jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output", + "Description": "jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.7, + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 9.6 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/security/cve/CVE-2026-42557", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477086", + "https://github.com/jupyterlab/jupyterlab", + "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg", + "https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-files", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42557", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42557.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42557" + ], + "PublishedDate": "2026-05-13T16:16:48.167Z", + "LastModifiedDate": "2026-07-22T12:17:56.103Z" + }, + { + "VulnerabilityID": "CVE-2026-25990", + "VendorIDs": [ + "GHSA-cfh3-3jmp-rvhc" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25990", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:6a7b96712ee0003bbc7bf13b434ad60e6831684e424e54ba25dcad3cb160de09", + "Title": "pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image", + "Description": "Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 7.3 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/02/12/1", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:14873", + "https://access.redhat.com/errata/RHSA-2026:14874", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:28385", + "https://access.redhat.com/errata/RHSA-2026:3461", + "https://access.redhat.com/errata/RHSA-2026:3462", + "https://access.redhat.com/errata/RHSA-2026:4128", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6308", + "https://access.redhat.com/errata/RHSA-2026:6309", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/security/cve/CVE-2026-25990", + "https://bugzilla.redhat.com/show_bug.cgi?id=2439170", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199", + "https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa", + "https://github.com/python-pillow/Pillow/pull/9427", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25990", + "https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json", + "https://ubuntu.com/security/notices/USN-8047-1", + "https://www.cve.org/CVERecord?id=CVE-2026-25990" + ], + "PublishedDate": "2026-02-11T21:16:20.67Z", + "LastModifiedDate": "2026-08-12T12:18:09.957Z" + }, + { + "VulnerabilityID": "CVE-2026-40192", + "VendorIDs": [ + "GHSA-whj4-6x5x-4v2j" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40192", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a319d9bf32c6eb085c19b18f3f773fcc0efb59b9ff3e625e54e14a72caae5d79", + "Title": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing", + "Description": "Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770", + "CWE-409" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:16008", + "https://access.redhat.com/errata/RHSA-2026:16009", + "https://access.redhat.com/errata/RHSA-2026:16030", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:17609", + "https://access.redhat.com/errata/RHSA-2026:17611", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22629", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24866", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:34366", + "https://access.redhat.com/errata/RHSA-2026:34368", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/security/cve/CVE-2026-40192", + "https://bugzilla.redhat.com/show_bug.cgi?id=2458856", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628", + "https://github.com/python-pillow/Pillow/pull/9521", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40192", + "https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json", + "https://ubuntu.com/security/notices/USN-8211-1", + "https://www.cve.org/CVERecord?id=CVE-2026-40192" + ], + "PublishedDate": "2026-04-15T23:16:10.053Z", + "LastModifiedDate": "2026-08-12T12:19:09.49Z" + }, + { + "VulnerabilityID": "CVE-2026-42311", + "VendorIDs": [ + "GHSA-pwv6-vv43-88gr" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.2.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42311", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f055ae1c16a266ca6bc1aa1501df92e1fa30054695d32ce0c1f57298af40f463", + "Title": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing", + "Description": "Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.6 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42311", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea", + "https://github.com/python-pillow/Pillow/pull/9520", + "https://github.com/python-pillow/Pillow/releases/tag/12.2.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42311", + "https://ubuntu.com/security/notices/USN-8399-1", + "https://www.cve.org/CVERecord?id=CVE-2026-42311" + ], + "PublishedDate": "2026-05-09T06:16:10.43Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-54058", + "VendorIDs": [ + "GHSA-62p4-gmf7-7g93" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54058", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:6f122b7b7f5773d0c5ee052ad8986e335b989fe67715a570266d51f6ec4f799c", + "Title": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-54058", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d", + "https://github.com/python-pillow/Pillow/pull/9719", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93", + "https://linux.oracle.com/cve/CVE-2026-54058.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54058", + "https://www.cve.org/CVERecord?id=CVE-2026-54058" + ], + "PublishedDate": "2026-07-14T17:17:03.433Z", + "LastModifiedDate": "2026-08-06T15:46:05.867Z" + }, + { + "VulnerabilityID": "CVE-2026-54059", + "VendorIDs": [ + "GHSA-8v84-f9pq-wr9x" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54059", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:a86f208b23d9eb7ec2b27ac1e2f1d7a32af0791e674970977d3fb98b473c7d53", + "Title": "python-pillow: Pillow: Denial of Service via crafted PCF font data", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54059", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2253.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x", + "https://linux.oracle.com/cve/CVE-2026-54059.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54059", + "https://www.cve.org/CVERecord?id=CVE-2026-54059" + ], + "PublishedDate": "2026-07-06T19:17:08.127Z", + "LastModifiedDate": "2026-07-07T18:58:26.73Z" + }, + { + "VulnerabilityID": "CVE-2026-54060", + "VendorIDs": [ + "GHSA-5x94-69rx-g8h2" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54060", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:ad6b0714e72f63b863026555b82793c1a9840808380166c7c6aa57b5db5889fe", + "Title": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-54060", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2", + "https://linux.oracle.com/cve/CVE-2026-54060.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54060", + "https://www.cve.org/CVERecord?id=CVE-2026-54060" + ], + "PublishedDate": "2026-07-06T19:17:08.27Z", + "LastModifiedDate": "2026-07-07T18:58:45.827Z" + }, + { + "VulnerabilityID": "CVE-2026-55379", + "VendorIDs": [ + "GHSA-45hq-cxwh-f6vc" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55379", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b9cd400a810f25ad12e17a29c1792160e2d801c14d04b031a0ec2b6eb00e0c21", + "Title": "python-pillow: Pillow: Denial of Service via crafted BDF font file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55379", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2255.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc", + "https://linux.oracle.com/cve/CVE-2026-55379.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55379", + "https://www.cve.org/CVERecord?id=CVE-2026-55379" + ], + "PublishedDate": "2026-07-06T19:17:08.577Z", + "LastModifiedDate": "2026-07-07T18:59:01.817Z" + }, + { + "VulnerabilityID": "CVE-2026-55380", + "VendorIDs": [ + "GHSA-phj9-mv4w-65pm" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-55380", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:f1288ce858c18e2bbe3d0d6fa167308ee2575231b5a96a838864b6473df28925", + "Title": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:39127", + "https://access.redhat.com/security/cve/CVE-2026-55380", + "https://bugzilla.redhat.com/2497452", + "https://bugzilla.redhat.com/2497455", + "https://bugzilla.redhat.com/2497464", + "https://bugzilla.redhat.com/2497466", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497452", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497455", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497464", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497466", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54059", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54060", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55379", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55380", + "https://errata.almalinux.org/8/ALSA-2026-39127.html", + "https://errata.rockylinux.org/RLSA-2026:39127", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2256.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst", + "https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm", + "https://linux.oracle.com/cve/CVE-2026-55380.html", + "https://linux.oracle.com/errata/ELSA-2026-39127.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-55380", + "https://www.cve.org/CVERecord?id=CVE-2026-55380" + ], + "PublishedDate": "2026-07-06T19:17:08.703Z", + "LastModifiedDate": "2026-07-07T18:58:54.647Z" + }, + { + "VulnerabilityID": "CVE-2026-59197", + "VendorIDs": [ + "GHSA-xj96-63gp-2gmr" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59197", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3dd0fa97200abc50f3c7b9ab0a3c32722608be4c60d9cde89343952a5846a1b1", + "Title": "Pillow: Pillow: Native heap out-of-bounds write", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:48021", + "https://access.redhat.com/security/cve/CVE-2026-59197", + "https://bugzilla.redhat.com/2500043", + "https://bugzilla.redhat.com/2500057", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500057", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54058", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59197", + "https://errata.almalinux.org/8/ALSA-2026-48021.html", + "https://errata.rockylinux.org/RLSA-2026:48021", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1", + "https://github.com/python-pillow/Pillow/pull/9695", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr", + "https://linux.oracle.com/cve/CVE-2026-59197.html", + "https://linux.oracle.com/errata/ELSA-2026-48021.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59197", + "https://www.cve.org/CVERecord?id=CVE-2026-59197" + ], + "PublishedDate": "2026-07-14T17:17:14.487Z", + "LastModifiedDate": "2026-07-21T19:17:11.907Z" + }, + { + "VulnerabilityID": "CVE-2026-59199", + "VendorIDs": [ + "GHSA-6r8x-57c9-28j4" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59199", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:ef84856202f3cb6ff5e5fdfbae1c978c30ec45d866d6c8fafbf10ff1ffcfd72c", + "Title": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190", + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59199", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3451.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b", + "https://github.com/python-pillow/Pillow/pull/9703", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59199", + "https://www.cve.org/CVERecord?id=CVE-2026-59199" + ], + "PublishedDate": "2026-07-14T16:17:01.937Z", + "LastModifiedDate": "2026-07-15T16:16:49.487Z" + }, + { + "VulnerabilityID": "CVE-2026-59200", + "VendorIDs": [ + "GHSA-jjj6-mw9f-p565" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59200", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:2949a2bff653790d5f9a4d204ff836e58ea2617091020fe32733a9a8afba4208", + "Title": "Pillow: Pillow: Denial of service via crafted PDF stream", + "Description": "Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59200", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09", + "https://github.com/python-pillow/Pillow/pull/9718", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59200", + "https://www.cve.org/CVERecord?id=CVE-2026-59200" + ], + "PublishedDate": "2026-07-14T17:17:14.62Z", + "LastModifiedDate": "2026-07-21T15:52:40.107Z" + }, + { + "VulnerabilityID": "CVE-2026-59204", + "VendorIDs": [ + "GHSA-vjc4-5qp5-m44j" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59204", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3599b467faea2a999ffab9f0242ca06b7ac3ea05798e99a3d125db5771e8e577", + "Title": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image", + "Description": "Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789", + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59204", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca", + "https://github.com/python-pillow/Pillow/pull/9704", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59204", + "https://www.cve.org/CVERecord?id=CVE-2026-59204" + ], + "PublishedDate": "2026-07-14T16:17:02.227Z", + "LastModifiedDate": "2026-07-21T19:17:12.02Z" + }, + { + "VulnerabilityID": "CVE-2026-59205", + "VendorIDs": [ + "GHSA-9hw9-ch79-4vh6" + ], + "PkgName": "pillow", + "PkgPath": "usr/local/lib/python3.12/site-packages/pillow-11.3.0.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/pillow@11.3.0", + "UID": "86bc784a1600a1e8" + }, + "InstalledVersion": "11.3.0", + "FixedVersion": "12.3.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-59205", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:81c1d6ead46c1e0d79f40031d8e33b352686839d686accfbcc833f45e6e52495", + "Title": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API", + "Description": "Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "amazon": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-59205", + "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3453.yaml", + "https://github.com/python-pillow/Pillow", + "https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721", + "https://github.com/python-pillow/Pillow/pull/9715", + "https://github.com/python-pillow/Pillow/releases/tag/12.3.0", + "https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6", + "https://nvd.nist.gov/vuln/detail/CVE-2026-59205", + "https://www.cve.org/CVERecord?id=CVE-2026-59205" + ], + "PublishedDate": "2026-07-14T16:17:02.37Z", + "LastModifiedDate": "2026-07-14T20:09:27.77Z" + }, + { + "VulnerabilityID": "CVE-2026-49476", + "VendorIDs": [ + "GHSA-2wc2-fm75-p42x" + ], + "PkgName": "soupsieve", + "PkgPath": "usr/local/lib/python3.12/site-packages/soupsieve-2.8.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/soupsieve@2.8.3", + "UID": "81e9bdba38fa2271" + }, + "InstalledVersion": "2.8.3", + "FixedVersion": "2.8.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49476", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:6ba1f8249f0e53188e4d840de4ec1a97420db3ab722cfe3c6a35a250be4ec4bc", + "Title": "python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string", + "Description": "Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-770" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-49476", + "https://github.com/facelessuser/soupsieve", + "https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39", + "https://github.com/facelessuser/soupsieve/releases/tag/2.8.4", + "https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x", + "https://nvd.nist.gov/vuln/detail/CVE-2026-49476", + "https://www.cve.org/CVERecord?id=CVE-2026-49476" + ], + "PublishedDate": "2026-07-14T21:17:01.877Z", + "LastModifiedDate": "2026-07-28T15:48:11.78Z" + }, + { + "VulnerabilityID": "CVE-2026-49477", + "VendorIDs": [ + "GHSA-836r-79rf-4m37" + ], + "PkgName": "soupsieve", + "PkgPath": "usr/local/lib/python3.12/site-packages/soupsieve-2.8.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/soupsieve@2.8.3", + "UID": "81e9bdba38fa2271" + }, + "InstalledVersion": "2.8.3", + "FixedVersion": "2.8.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49477", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:26e30d07d9cfb3308d7e71bab633babe7ad24c9ef9cb1bb207d0a9e6bffd4984", + "Title": "soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings", + "Description": "Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-1333" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-49477", + "https://github.com/facelessuser/soupsieve", + "https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3", + "https://github.com/facelessuser/soupsieve/releases/tag/2.8.4", + "https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37", + "https://nvd.nist.gov/vuln/detail/CVE-2026-49477", + "https://www.cve.org/CVERecord?id=CVE-2026-49477" + ], + "PublishedDate": "2026-07-14T21:17:02.007Z", + "LastModifiedDate": "2026-07-28T15:48:00.76Z" + }, + { + "VulnerabilityID": "CVE-2026-31958", + "VendorIDs": [ + "GHSA-qjxf-f2mg-c6mc" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.5.4", + "UID": "6b29a8d722c546a" + }, + "InstalledVersion": "6.5.4", + "FixedVersion": "6.5.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-31958", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9a48ca68bf7d3aed073397171d3a725bdca153be7ce28b11d746c7ad2bd50630", + "Title": "tornado-python: Tornado: Denial of Service via large multipart bodies", + "Description": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 5.3 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:19189", + "https://access.redhat.com/security/cve/CVE-2026-31958", + "https://bugzilla.redhat.com/2446765", + "https://bugzilla.redhat.com/2454716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", + "https://bugzilla.redhat.com/show_bug.cgi?id=2454716", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31958", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35536", + "https://errata.almalinux.org/9/ALSA-2026-19189.html", + "https://errata.rockylinux.org/RLSA-2026:19189", + "https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2026-140.yaml", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc", + "https://linux.oracle.com/cve/CVE-2026-31958.html", + "https://linux.oracle.com/errata/ELSA-2026-8093.html", + "https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-31958", + "https://ubuntu.com/security/notices/USN-8198-1", + "https://ubuntu.com/security/notices/USN-8198-2", + "https://www.cve.org/CVERecord?id=CVE-2026-31958" + ], + "PublishedDate": "2026-03-11T20:16:16.617Z", + "LastModifiedDate": "2026-06-17T10:34:50.473Z" + }, + { + "VulnerabilityID": "CVE-2026-35536", + "VendorIDs": [ + "GHSA-fqwm-6jpj-5wxc" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.5.4", + "UID": "6b29a8d722c546a" + }, + "InstalledVersion": "6.5.4", + "FixedVersion": "6.5.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-35536", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:959d47e96a96fa3bb6adfa8da6464881987a63b875477157c757b96530aa8947", + "Title": "tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments", + "Description": "In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-159" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "photon": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N", + "V3Score": 7.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", + "V3Score": 5.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:19189", + "https://access.redhat.com/security/cve/CVE-2026-35536", + "https://bugzilla.redhat.com/2446765", + "https://bugzilla.redhat.com/2454716", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446765", + "https://bugzilla.redhat.com/show_bug.cgi?id=2454716", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31958", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35536", + "https://errata.almalinux.org/9/ALSA-2026-19189.html", + "https://errata.rockylinux.org/RLSA-2026:19189", + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7", + "https://linux.oracle.com/cve/CVE-2026-35536.html", + "https://linux.oracle.com/errata/ELSA-2026-24342.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-35536", + "https://ubuntu.com/security/notices/USN-8198-1", + "https://ubuntu.com/security/notices/USN-8198-2", + "https://www.cve.org/CVERecord?id=CVE-2026-35536" + ], + "PublishedDate": "2026-04-03T04:16:53.55Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-49853", + "VendorIDs": [ + "GHSA-3x9g-8vmp-wqvf" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.5.4", + "UID": "6b29a8d722c546a" + }, + "InstalledVersion": "6.5.4", + "FixedVersion": "6.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49853", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:bdebf6c8ceb3f3957b6426cac43d65b61bdef22946110746b0c25528dfd546fa", + "Title": "Tornado is a Python web framework and asynchronous networking library. ...", + "Description": "Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "photon": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N", + "V3Score": 7.7 + } + }, + "References": [ + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/aba2569f7ed7a6bdbef816658fb6b7182531b751", + "https://github.com/tornadoweb/tornado/pull/3626", + "https://github.com/tornadoweb/tornado/releases/tag/v6.5.6", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf" + ], + "PublishedDate": "2026-07-14T21:17:02.13Z", + "LastModifiedDate": "2026-07-21T16:17:13.477Z" + }, + { + "VulnerabilityID": "CVE-2026-49855", + "VendorIDs": [ + "GHSA-mgf9-4vpg-hj56" + ], + "PkgName": "tornado", + "PkgPath": "usr/local/lib/python3.12/site-packages/tornado-6.5.4.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/tornado@6.5.4", + "UID": "6b29a8d722c546a" + }, + "InstalledVersion": "6.5.4", + "FixedVersion": "6.5.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49855", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:c8ec8742b1d5672294835b50a5bb1e5d2960ad1601e15934a81b4bda1641d3bd", + "Title": "Tornado is a Python web framework and asynchronous networking library. ...", + "Description": "Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "photon": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/tornadoweb/tornado", + "https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff", + "https://github.com/tornadoweb/tornado/pull/3626", + "https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56" + ], + "PublishedDate": "2026-07-14T21:17:02.437Z", + "LastModifiedDate": "2026-07-16T16:19:10.69Z" + }, + { + "VulnerabilityID": "CVE-2026-44431", + "VendorIDs": [ + "GHSA-qccp-gfcp-xxvc" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.6.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.6.3", + "UID": "edbb32dd3713915e" + }, + "InstalledVersion": "2.6.3", + "FixedVersion": "2.7.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44431", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:be2e9b78f8efdb553d91b40a602522c1b96beb27391b2a84907fd553fd254df6", + "Title": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers", + "Description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V3Score": 5.3, + "V40Score": 8.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:28158", + "https://access.redhat.com/errata/RHSA-2026:28159", + "https://access.redhat.com/security/cve/CVE-2026-44431", + "https://bugzilla.redhat.com/2477154", + "https://bugzilla.redhat.com/2477167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477154", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477167", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432", + "https://errata.almalinux.org/9/ALSA-2026-28159.html", + "https://errata.rockylinux.org/RLSA-2026:28158", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc", + "https://linux.oracle.com/cve/CVE-2026-44431.html", + "https://linux.oracle.com/errata/ELSA-2026-49927.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44431", + "https://ubuntu.com/security/notices/USN-8379-1", + "https://www.cve.org/CVERecord?id=CVE-2026-44431" + ], + "PublishedDate": "2026-05-13T16:16:57.15Z", + "LastModifiedDate": "2026-06-26T12:16:32.423Z" + }, + { + "VulnerabilityID": "CVE-2026-44432", + "VendorIDs": [ + "GHSA-mf9v-mfxr-j63j" + ], + "PkgName": "urllib3", + "PkgPath": "usr/local/lib/python3.12/site-packages/urllib3-2.6.3.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/urllib3@2.6.3", + "UID": "edbb32dd3713915e" + }, + "InstalledVersion": "2.6.3", + "FixedVersion": "2.7.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6d6726d31edbd42d1a6ef6e8e95da36b2ece605a70847481f52e5720690257a4", + "DiffID": "sha256:cdfddd94cec2b2ec02f3f41f9ffa5a6af17c6ebe1c0c60d0749803b4159eb3f2" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-44432", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3a0606dd7e7dce2dc743146b7ff582508883f7127543035349d9de25b409c95a", + "Title": "urllib3: urllib3: Denial of Service due to excessive HTTP response decompression", + "Description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V3Score": 7.5, + "V40Score": 8.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:15862", + "https://access.redhat.com/errata/RHSA-2026:20338", + "https://access.redhat.com/errata/RHSA-2026:22934", + "https://access.redhat.com/errata/RHSA-2026:24000", + "https://access.redhat.com/errata/RHSA-2026:24009", + "https://access.redhat.com/errata/RHSA-2026:24014", + "https://access.redhat.com/errata/RHSA-2026:24069", + "https://access.redhat.com/errata/RHSA-2026:24374", + "https://access.redhat.com/errata/RHSA-2026:24476", + "https://access.redhat.com/errata/RHSA-2026:24483", + "https://access.redhat.com/errata/RHSA-2026:24540", + "https://access.redhat.com/errata/RHSA-2026:24541", + "https://access.redhat.com/errata/RHSA-2026:24542", + "https://access.redhat.com/errata/RHSA-2026:24544", + "https://access.redhat.com/errata/RHSA-2026:25039", + "https://access.redhat.com/errata/RHSA-2026:25143", + "https://access.redhat.com/errata/RHSA-2026:25928", + "https://access.redhat.com/errata/RHSA-2026:26212", + "https://access.redhat.com/errata/RHSA-2026:26304", + "https://access.redhat.com/errata/RHSA-2026:27929", + "https://access.redhat.com/errata/RHSA-2026:28000", + "https://access.redhat.com/errata/RHSA-2026:28157", + "https://access.redhat.com/errata/RHSA-2026:28158", + "https://access.redhat.com/errata/RHSA-2026:28159", + "https://access.redhat.com/errata/RHSA-2026:28571", + "https://access.redhat.com/errata/RHSA-2026:30076", + "https://access.redhat.com/errata/RHSA-2026:30078", + "https://access.redhat.com/errata/RHSA-2026:30087", + "https://access.redhat.com/errata/RHSA-2026:30088", + "https://access.redhat.com/errata/RHSA-2026:30089", + "https://access.redhat.com/errata/RHSA-2026:32992", + "https://access.redhat.com/errata/RHSA-2026:33313", + "https://access.redhat.com/errata/RHSA-2026:33683", + "https://access.redhat.com/errata/RHSA-2026:34160", + "https://access.redhat.com/errata/RHSA-2026:34374", + "https://access.redhat.com/errata/RHSA-2026:34526", + "https://access.redhat.com/errata/RHSA-2026:34531", + "https://access.redhat.com/errata/RHSA-2026:34533", + "https://access.redhat.com/errata/RHSA-2026:34607", + "https://access.redhat.com/errata/RHSA-2026:36350", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42144", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:44481", + "https://access.redhat.com/errata/RHSA-2026:51206", + "https://access.redhat.com/errata/RHSA-2026:7625", + "https://access.redhat.com/errata/RHSA-2026:7634", + "https://access.redhat.com/security/cve/CVE-2026-44432", + "https://bugzilla.redhat.com/2477154", + "https://bugzilla.redhat.com/2477167", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477154", + "https://bugzilla.redhat.com/show_bug.cgi?id=2477167", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432", + "https://errata.almalinux.org/9/ALSA-2026-28159.html", + "https://errata.rockylinux.org/RLSA-2026:28158", + "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml", + "https://github.com/urllib3/urllib3", + "https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j", + "https://linux.oracle.com/cve/CVE-2026-44432.html", + "https://linux.oracle.com/errata/ELSA-2026-32992.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-44432", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json", + "https://ubuntu.com/security/notices/USN-8379-1", + "https://www.cve.org/CVERecord?id=CVE-2026-44432" + ], + "PublishedDate": "2026-05-13T16:16:57.303Z", + "LastModifiedDate": "2026-08-12T12:19:21.683Z" + } + ], + "vulnerability_count": 37 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 37 + } +} diff --git a/bfx/ismapper/trivy-scan-results.json b/bfx/ismapper/trivy-scan-results.json new file mode 100644 index 00000000..693bbd2b --- /dev/null +++ b/bfx/ismapper/trivy-scan-results.json @@ -0,0 +1,830 @@ +{ + "tool": "ismapper", + "scan_timestamp": "2026-08-16T17:09:04Z", + "workflow_run_id": "31960542324", + "versions": { + "2.0": { + "image": "ghcr.io/bundlecore/products/bfx/ismapper:2.0", + "vulnerabilities": [ + { + "VulnerabilityID": "CVE-2023-37920", + "VendorIDs": [ + "GHSA-xqr8-7jwr-rhp7" + ], + "PkgName": "certifi", + "PkgPath": "usr/local/lib/python3.7/site-packages/certifi-2019.03.09-py3.7.egg-info", + "PkgIdentifier": { + "PURL": "pkg:pypi/certifi@2019.03.09", + "UID": "a591b89aa1c7a4e0" + }, + "InstalledVersion": "2019.03.09", + "FixedVersion": "2023.7.22", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2023-37920", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:3a7dc9f0cca7b9dd660b925e858cd585ec5f2be8a4755ef21b8048f59b7620f0", + "Title": "python-certifi: Removal of e-Tugra root certificate", + "Description": "Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes \"e-Tugra\" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from \"e-Tugra\" from the root store.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-345" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 4, + "ghsa": 3, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 1 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:7753", + "https://access.redhat.com/security/cve/CVE-2023-37920", + "https://bugzilla.redhat.com/2226586", + "https://bugzilla.redhat.com/2242493", + "https://errata.almalinux.org/9/ALSA-2023-7753.html", + "https://github.com/certifi/python-certifi", + "https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909", + "https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7", + "https://github.com/pypa/advisory-database/tree/main/vulns/certifi/PYSEC-2023-135.yaml", + "https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A", + "https://linux.oracle.com/cve/CVE-2023-37920.html", + "https://linux.oracle.com/errata/ELSA-2024-0133.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/", + "https://nvd.nist.gov/vuln/detail/CVE-2023-37920", + "https://security.netapp.com/advisory/ntap-20240912-0002", + "https://security.netapp.com/advisory/ntap-20240912-0002/", + "https://www.cve.org/CVERecord?id=CVE-2023-37920" + ], + "PublishedDate": "2023-07-25T21:15:10.827Z", + "LastModifiedDate": "2026-06-17T06:08:54.337Z" + }, + { + "VulnerabilityID": "CVE-2019-6446", + "VendorIDs": [ + "GHSA-9fq2-x9r6-wfmf" + ], + "PkgName": "numpy", + "PkgPath": "usr/local/lib/python3.7/site-packages/numpy-1.16.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/numpy@1.16.2", + "UID": "24b2f5c532df4dd3" + }, + "InstalledVersion": "1.16.2", + "FixedVersion": "1.16.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-6446", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b0a08d5aafdc578e46053118c43e13335a8ab1eaa547384cdc70e180362e6761", + "Title": "numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution", + "Description": "An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-502" + ], + "VendorSeverity": { + "alma": 2, + "ghsa": 4, + "nvd": 4, + "oracle-oval": 2, + "redhat": 2, + "rocky": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 9.8, + "V40Score": 9.3 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P", + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V2Score": 7.5, + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00091.html", + "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00092.html", + "http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00015.html", + "http://www.securityfocus.com/bid/106670", + "https://access.redhat.com/errata/RHSA-2019:3335", + "https://access.redhat.com/errata/RHSA-2019:3704", + "https://access.redhat.com/security/cve/CVE-2019-6446", + "https://bugzilla.redhat.com/show_bug.cgi?id=1667950", + "https://bugzilla.redhat.com/show_bug.cgi?id=1680967", + "https://bugzilla.redhat.com/show_bug.cgi?id=1688169", + "https://bugzilla.redhat.com/show_bug.cgi?id=1695570", + "https://bugzilla.redhat.com/show_bug.cgi?id=1695572", + "https://bugzilla.redhat.com/show_bug.cgi?id=1700824", + "https://bugzilla.redhat.com/show_bug.cgi?id=1700993", + "https://bugzilla.redhat.com/show_bug.cgi?id=1702473", + "https://bugzilla.redhat.com/show_bug.cgi?id=1709599", + "https://bugzilla.redhat.com/show_bug.cgi?id=1718398", + "https://bugzilla.redhat.com/show_bug.cgi?id=1734126", + "https://bugzilla.suse.com/show_bug.cgi?id=1122208", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11236", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11324", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6446", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9740", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9947", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9948", + "https://errata.almalinux.org/8/ALSA-2019-3335.html", + "https://errata.rockylinux.org/RLSA-2019:3335", + "https://github.com/advisories/GHSA-9fq2-x9r6-wfmf", + "https://github.com/numpy/numpy", + "https://github.com/numpy/numpy/commit/89b688732b37616c9d26623f81aaee1703c30ffb", + "https://github.com/numpy/numpy/issues/12759", + "https://github.com/numpy/numpy/pull/12889", + "https://github.com/numpy/numpy/pull/13359", + "https://github.com/pypa/advisory-database/tree/main/vulns/numpy/PYSEC-2019-108.yaml", + "https://linux.oracle.com/cve/CVE-2019-6446.html", + "https://linux.oracle.com/errata/ELSA-2019-3704.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZZAYIQNUUYXGMKHSPEEXS4TRYFOUYE4", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZZAYIQNUUYXGMKHSPEEXS4TRYFOUYE4/", + "https://nvd.nist.gov/vuln/detail/CVE-2019-6446", + "https://web.archive.org/web/20210124234613/https://www.securityfocus.com/bid/106670", + "https://www.cve.org/CVERecord?id=CVE-2019-6446" + ], + "PublishedDate": "2019-01-16T05:29:01.37Z", + "LastModifiedDate": "2026-06-17T02:39:03.863Z" + }, + { + "VulnerabilityID": "CVE-2021-41495", + "VendorIDs": [ + "GHSA-5545-2q6w-2gh6" + ], + "PkgName": "numpy", + "PkgPath": "usr/local/lib/python3.7/site-packages/numpy-1.16.2.dist-info/METADATA", + "PkgIdentifier": { + "PURL": "pkg:pypi/numpy@1.16.2", + "UID": "24b2f5c532df4dd3" + }, + "InstalledVersion": "1.16.2", + "FixedVersion": "1.19", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-41495", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:2b03196b92441c346db7eba2423a395118a47cd218c8347146989aacd6ef987b", + "Title": "numpy: NULL pointer dereference in numpy.sort in in the PyArray_DescrNew() due to missing return-value validation", + "Description": "Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:S/C:N/I:N/A:P", + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V2Score": 3.5, + "V3Score": 5.3 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2021-41495", + "https://github.com/advisories/GHSA-5545-2q6w-2gh6", + "https://github.com/numpy/numpy", + "https://github.com/numpy/numpy/issues/19038", + "https://github.com/numpy/numpy/pull/20960", + "https://github.com/numpy/numpy/pull/20984%20%28backport%29", + "https://github.com/pypa/advisory-database/tree/main/vulns/numpy/PYSEC-2021-856.yaml", + "https://nvd.nist.gov/vuln/detail/CVE-2021-41495", + "https://ubuntu.com/security/notices/USN-5763-1", + "https://www.cve.org/CVERecord?id=CVE-2021-41495", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-12-17T20:15:08.477Z", + "LastModifiedDate": "2026-06-17T04:08:33.897Z" + }, + { + "VulnerabilityID": "CVE-2019-20916", + "VendorIDs": [ + "GHSA-gpvv-69j7-gwj8" + ], + "PkgName": "pip", + "PkgPath": "usr/local/lib/python3.7/site-packages/pip-19.0.3-py3.7.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/pip@19.0.3", + "UID": "291ccab574b2ca77" + }, + "InstalledVersion": "19.0.3", + "FixedVersion": "19.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2019-20916", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:2ad5056645bd10686a12a18eb59d6570018d30f1fac467f511369b976e2ba124", + "Title": "python-pip: directory traversal in _download_http_url() function in src/pip/_internal/download.py", + "Description": "The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V2Vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V2Score": 5, + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8 + } + }, + "References": [ + "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00005.html", + "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00010.html", + "https://access.redhat.com/security/cve/CVE-2019-20916", + "https://bugzilla.redhat.com/show_bug.cgi?id=1856481", + "https://bugzilla.redhat.com/show_bug.cgi?id=1868135", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20907", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20916", + "https://errata.almalinux.org/8/ALSA-2020-4654.html", + "https://errata.rockylinux.org/RLSA-2020:4654", + "https://github.com/advisories/GHSA-gpvv-69j7-gwj8", + "https://github.com/gzpan123/pip/commit/a4c735b14a62f9cb864533808ac63936704f2ace", + "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2020-173.yaml", + "https://github.com/pypa/pip", + "https://github.com/pypa/pip/commit/a4c735b14a62f9cb864533808ac63936704f2ace%20%2819.2%29", + "https://github.com/pypa/pip/compare/19.1.1...19.2", + "https://github.com/pypa/pip/issues/6413", + "https://linux.oracle.com/cve/CVE-2019-20916.html", + "https://linux.oracle.com/errata/ELSA-2022-9204.html", + "https://lists.debian.org/debian-lts-announce/2020/09/msg00010.html", + "https://nvd.nist.gov/vuln/detail/CVE-2019-20916", + "https://ubuntu.com/security/notices/USN-4601-1", + "https://www.cve.org/CVERecord?id=CVE-2019-20916", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2020-09-04T20:15:11.013Z", + "LastModifiedDate": "2026-06-17T02:31:25.907Z" + }, + { + "VulnerabilityID": "CVE-2021-3572", + "VendorIDs": [ + "GHSA-5xp3-jfq3-5q8x" + ], + "PkgName": "pip", + "PkgPath": "usr/local/lib/python3.7/site-packages/pip-19.0.3-py3.7.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/pip@19.0.3", + "UID": "291ccab574b2ca77" + }, + "InstalledVersion": "19.0.3", + "FixedVersion": "21.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-3572", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:8c3e70f0521e7ff0c5e0074dc0724a7c1636d55df25365a7013267ea519f5308", + "Title": "python-pip: Incorrect handling of unicode separators in git references", + "Description": "A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20" + ], + "VendorSeverity": { + "alma": 1, + "amazon": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 3, + "redhat": 1, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N", + "V3Score": 5.7, + "V40Score": 7.1 + }, + "nvd": { + "V2Vector": "AV:N/AC:M/Au:S/C:N/I:P/A:N", + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N", + "V2Score": 3.5, + "V3Score": 5.7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N", + "V3Score": 4.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2021:3254", + "https://access.redhat.com/security/cve/CVE-2021-3572", + "https://bugzilla.redhat.com/show_bug.cgi?id=1772014", + "https://bugzilla.redhat.com/show_bug.cgi?id=1928707", + "https://bugzilla.redhat.com/show_bug.cgi?id=1928904", + "https://bugzilla.redhat.com/show_bug.cgi?id=1935913", + "https://bugzilla.redhat.com/show_bug.cgi?id=1941534", + "https://bugzilla.redhat.com/show_bug.cgi?id=1955615", + "https://bugzilla.redhat.com/show_bug.cgi?id=1957458", + "https://bugzilla.redhat.com/show_bug.cgi?id=1962856", + "https://bugzilla.redhat.com/show_bug.cgi?id=1968074", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27619", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28493", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20095", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23336", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28957", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29921", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33503", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3426", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3572", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42771", + "https://errata.rockylinux.org/RLSA-2021:4162", + "https://github.com/advisories/GHSA-5xp3-jfq3-5q8x", + "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2021-437.yaml", + "https://github.com/pypa/pip", + "https://github.com/pypa/pip/commit/e46bdda9711392fec0c45c1175bae6db847cb30b", + "https://github.com/pypa/pip/issues/10042", + "https://github.com/pypa/pip/issues/10042#issuecomment-857452480", + "https://github.com/pypa/pip/pull/9827", + "https://github.com/skazi0/CVE-2021-3572/blob/master/CVE-2021-3572-v9.0.1.patch", + "https://linux.oracle.com/cve/CVE-2021-3572.html", + "https://linux.oracle.com/errata/ELSA-2023-12349.html", + "https://nvd.nist.gov/vuln/detail/CVE-2021-3572", + "https://packetstormsecurity.com/files/162712/USN-4961-1.txt", + "https://security.netapp.com/advisory/ntap-20240621-0006", + "https://security.netapp.com/advisory/ntap-20240621-0006/", + "https://ubuntu.com/security/notices/USN-4961-2", + "https://www.cve.org/CVERecord?id=CVE-2021-3572", + "https://www.oracle.com/security-alerts/cpuapr2022.html", + "https://www.oracle.com/security-alerts/cpujul2022.html" + ], + "PublishedDate": "2021-11-10T18:15:09.51Z", + "LastModifiedDate": "2026-06-17T04:05:21.91Z" + }, + { + "VulnerabilityID": "CVE-2022-40897", + "VendorIDs": [ + "GHSA-r9hx-vwmv-q579" + ], + "PkgName": "setuptools", + "PkgPath": "usr/local/lib/python3.7/site-packages/setuptools-40.8.0-py3.7.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@40.8.0", + "UID": "d5bc24e739287db7" + }, + "InstalledVersion": "40.8.0", + "FixedVersion": "65.5.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-40897", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b7be0e9199f33eeb600988da9646c1c3c71630cbbbe4c53e5162b96386bfcc3f", + "Title": "pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py", + "Description": "Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1333" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "bitnami": 2, + "cbl-mariner": 2, + "ghsa": 3, + "nvd": 2, + "oracle-oval": 2, + "photon": 2, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:L/SI:L/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:0952", + "https://access.redhat.com/security/cve/CVE-2022-40897", + "https://bugzilla.redhat.com/2158559", + "https://bugzilla.redhat.com/show_bug.cgi?id=2158559", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40897", + "https://errata.almalinux.org/9/ALSA-2023-0952.html", + "https://errata.rockylinux.org/RLSA-2023:0952", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2022-43012.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/fe8a98e696241487ba6ac9f91faa38ade939ec5d/setuptools/package_index.py#L200", + "https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be", + "https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1", + "https://github.com/pypa/setuptools/issues/3659", + "https://linux.oracle.com/cve/CVE-2022-40897.html", + "https://linux.oracle.com/errata/ELSA-2024-2987.html", + "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R/", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H", + "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H/", + "https://nvd.nist.gov/vuln/detail/CVE-2022-40897", + "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages", + "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/", + "https://pyup.io/vulnerabilities/CVE-2022-40897/52495", + "https://pyup.io/vulnerabilities/CVE-2022-40897/52495/", + "https://security.netapp.com/advisory/ntap-20230214-0001", + "https://security.netapp.com/advisory/ntap-20230214-0001/", + "https://security.netapp.com/advisory/ntap-20240621-0006", + "https://security.netapp.com/advisory/ntap-20240621-0006/", + "https://setuptools.pypa.io/en/latest", + "https://ubuntu.com/security/notices/USN-5817-1", + "https://www.cve.org/CVERecord?id=CVE-2022-40897" + ], + "PublishedDate": "2022-12-23T00:15:13.987Z", + "LastModifiedDate": "2026-06-17T05:02:12.993Z" + }, + { + "VulnerabilityID": "CVE-2024-6345", + "VendorIDs": [ + "GHSA-cx63-2mw6-8hw5" + ], + "PkgName": "setuptools", + "PkgPath": "usr/local/lib/python3.7/site-packages/setuptools-40.8.0-py3.7.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@40.8.0", + "UID": "d5bc24e739287db7" + }, + "InstalledVersion": "40.8.0", + "FixedVersion": "70.0.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2024-6345", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:846038c1f85160c55915550a113c79703b8cf103dfbec4f808d1ba45487c4215", + "Title": "pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools", + "Description": "A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-94" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "ghsa": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V3Score": 8.8, + "V40Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2024:6726", + "https://access.redhat.com/security/cve/CVE-2024-6345", + "https://bugzilla.redhat.com/2297771", + "https://bugzilla.redhat.com/show_bug.cgi?id=2297771", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6345", + "https://errata.almalinux.org/9/ALSA-2024-6726.html", + "https://errata.rockylinux.org/RLSA-2024:6726", + "https://github.com/advisories/GHSA-cx63-2mw6-8hw5", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0", + "https://github.com/pypa/setuptools/pull/4332", + "https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5", + "https://linux.oracle.com/cve/CVE-2024-6345.html", + "https://linux.oracle.com/errata/ELSA-2024-6726.html", + "https://lists.debian.org/debian-lts-announce/2024/09/msg00018.html", + "https://nvd.nist.gov/vuln/detail/CVE-2024-6345", + "https://ubuntu.com/security/notices/USN-7002-1", + "https://www.cve.org/CVERecord?id=CVE-2024-6345" + ], + "PublishedDate": "2024-07-15T01:15:01.73Z", + "LastModifiedDate": "2026-06-17T08:17:49.463Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgName": "setuptools", + "PkgPath": "usr/local/lib/python3.7/site-packages/setuptools-40.8.0-py3.7.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@40.8.0", + "UID": "d5bc24e739287db7" + }, + "InstalledVersion": "40.8.0", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:500c12473a7bf7003979cef13c6d0b110cc2597c39a95e8ae7e32ab1b3f76e7c", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:13578", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/9/ALSA-2025-13578.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + }, + { + "VulnerabilityID": "CVE-2022-40898", + "VendorIDs": [ + "GHSA-qwmp-2cf2-g9g6" + ], + "PkgName": "wheel", + "PkgPath": "usr/local/lib/python3.7/site-packages/wheel-0.33.1-py3.7.egg-info/PKG-INFO", + "PkgIdentifier": { + "PURL": "pkg:pypi/wheel@0.33.1", + "UID": "5df3ec073ac4694" + }, + "InstalledVersion": "0.33.1", + "FixedVersion": "0.38.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1532c500d43f1891171887aa7d0f6a86c49820c19d2a5af5c3d1f6f9aae26912", + "DiffID": "sha256:b887c8dcddaeebbdedcd7f7ec4f0a1db925f1ce746c54a2d4718d781bbcc7fa8" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2022-40898", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:b4b768c94708ffaf74145609007c48cc396ce03dde82564325db5fa0fbc47451", + "Title": "python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli", + "Description": "An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-20" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2023:6712", + "https://access.redhat.com/security/cve/CVE-2022-40898", + "https://bugzilla.redhat.com/2165864", + "https://errata.almalinux.org/9/ALSA-2023-6712.html", + "https://github.com/advisories/GHSA-qwmp-2cf2-g9g6", + "https://github.com/pypa/advisory-database/tree/main/vulns/wheel/PYSEC-2022-43017.yaml", + "https://github.com/pypa/wheel", + "https://github.com/pypa/wheel/blob/main/src/wheel/wheelfile.py#L18", + "https://github.com/pypa/wheel/commit/88f02bc335d5404991e532e7f3b0fc80437bf4e0", + "https://linux.oracle.com/cve/CVE-2022-40898.html", + "https://linux.oracle.com/errata/ELSA-2023-6712.html", + "https://nvd.nist.gov/vuln/detail/CVE-2022-40898", + "https://pypi.org/project/wheel", + "https://pypi.org/project/wheel/", + "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages", + "https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/", + "https://pyup.io/vulnerabilities/CVE-2022-40898/51499", + "https://ubuntu.com/security/notices/USN-5821-1", + "https://ubuntu.com/security/notices/USN-5821-2", + "https://ubuntu.com/security/notices/USN-5821-3", + "https://www.cve.org/CVERecord?id=CVE-2022-40898" + ], + "PublishedDate": "2022-12-23T00:15:14.043Z", + "LastModifiedDate": "2026-06-17T05:02:13.177Z" + } + ], + "vulnerability_count": 9 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 9 + } +} diff --git a/bfx/isoquant/trivy-scan-results.json b/bfx/isoquant/trivy-scan-results.json new file mode 100644 index 00000000..75961056 --- /dev/null +++ b/bfx/isoquant/trivy-scan-results.json @@ -0,0 +1,153 @@ +{ + "tool": "isoquant", + "scan_timestamp": "2026-08-16T17:09:16Z", + "workflow_run_id": "31960542324", + "versions": { + "4.0.0": { + "image": "ghcr.io/bundlecore/products/bfx/isoquant:4.0.0", + "vulnerabilities": [ + { + "VulnerabilityID": "GHSA-6v7p-g79w-8964", + "PkgID": "msgpack@1.1.2", + "PkgName": "msgpack", + "PkgIdentifier": { + "PURL": "pkg:pypi/msgpack@1.1.2", + "UID": "33820b693fb1213e", + "BOMRef": "pkg:pypi/msgpack@1.1.2" + }, + "InstalledVersion": "1.1.2", + "FixedVersion": "1.2.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:f4216eb47f4f923f632ade69c3fed39e9b266f97f4cfc757583fdb448df5b9c8", + "DiffID": "sha256:1a882f85bfcff5f7d3474bb4cd33b636ab77062b8d714b0e8360d3ce3303ee79" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-6v7p-g79w-8964", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:7514a54d912b61de85e2de03f876cd2d5e20106ee389b8ca5abec0d6d5eccae3", + "Title": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error", + "Description": "### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.\n\nTherefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/msgpack/msgpack-python", + "https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d", + "https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1", + "https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964" + ], + "PublishedDate": "2026-06-19T21:42:55Z", + "LastModifiedDate": "2026-06-19T21:42:55Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgID": "setuptools@70.3.0", + "PkgName": "setuptools", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@70.3.0", + "UID": "ed58bcdeda2bae2f", + "BOMRef": "pkg:pypi/setuptools@70.3.0" + }, + "InstalledVersion": "70.3.0", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:f4216eb47f4f923f632ade69c3fed39e9b266f97f4cfc757583fdb448df5b9c8", + "DiffID": "sha256:1a882f85bfcff5f7d3474bb4cd33b636ab77062b8d714b0e8360d3ce3303ee79" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:d290066a95c769764ed40219813c79401347fabd6a78ca3125587eb7c7802600", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:13578", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/9/ALSA-2025-13578.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + } + ], + "vulnerability_count": 2 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 2 + } +} diff --git a/bfx/ivar/trivy-scan-results.json b/bfx/ivar/trivy-scan-results.json new file mode 100644 index 00000000..a6a74f98 --- /dev/null +++ b/bfx/ivar/trivy-scan-results.json @@ -0,0 +1,16 @@ +{ + "tool": "ivar", + "scan_timestamp": "2026-08-16T17:09:32Z", + "workflow_run_id": "31960542324", + "versions": { + "1.4.4": { + "image": "ghcr.io/bundlecore/products/bfx/ivar:1.4.4", + "vulnerabilities": [], + "vulnerability_count": 0 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kaiju/trivy-scan-results.json b/bfx/kaiju/trivy-scan-results.json new file mode 100644 index 00000000..02ca8a12 --- /dev/null +++ b/bfx/kaiju/trivy-scan-results.json @@ -0,0 +1,16 @@ +{ + "tool": "kaiju", + "scan_timestamp": "2026-08-16T17:09:35Z", + "workflow_run_id": "31960542324", + "versions": { + "1.10.2": { + "image": "ghcr.io/bundlecore/products/bfx/kaiju:1.10.2", + "vulnerabilities": [], + "vulnerability_count": 0 + } + }, + "summary": { + "total_versions_scanned": 1, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kentutils/trivy-scan-results.json b/bfx/kentutils/trivy-scan-results.json new file mode 100644 index 00000000..b81490f0 --- /dev/null +++ b/bfx/kentutils/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "kentutils", + "scan_timestamp": "2026-08-16T17:09:41Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/khmer/trivy-scan-results.json b/bfx/khmer/trivy-scan-results.json new file mode 100644 index 00000000..a8b2c860 --- /dev/null +++ b/bfx/khmer/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "khmer", + "scan_timestamp": "2026-08-16T17:09:42Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kissplice/trivy-scan-results.json b/bfx/kissplice/trivy-scan-results.json new file mode 100644 index 00000000..4f18e648 --- /dev/null +++ b/bfx/kissplice/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "kissplice", + "scan_timestamp": "2026-08-16T17:09:43Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kma/trivy-scan-results.json b/bfx/kma/trivy-scan-results.json new file mode 100644 index 00000000..ea842b67 --- /dev/null +++ b/bfx/kma/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "kma", + "scan_timestamp": "2026-08-16T17:09:43Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kmc/trivy-scan-results.json b/bfx/kmc/trivy-scan-results.json new file mode 100644 index 00000000..93e20c28 --- /dev/null +++ b/bfx/kmc/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "kmc", + "scan_timestamp": "2026-08-16T17:09:44Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kmer-jellyfish/trivy-scan-results.json b/bfx/kmer-jellyfish/trivy-scan-results.json new file mode 100644 index 00000000..3f91956c --- /dev/null +++ b/bfx/kmer-jellyfish/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "kmer-jellyfish", + "scan_timestamp": "2026-08-16T17:09:45Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kmergenie/trivy-scan-results.json b/bfx/kmergenie/trivy-scan-results.json new file mode 100644 index 00000000..69c7be6d --- /dev/null +++ b/bfx/kmergenie/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "kmergenie", + "scan_timestamp": "2026-08-16T17:09:46Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kneaddata/trivy-scan-results.json b/bfx/kneaddata/trivy-scan-results.json new file mode 100644 index 00000000..f2d489d2 --- /dev/null +++ b/bfx/kneaddata/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "kneaddata", + "scan_timestamp": "2026-08-16T17:09:47Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/kover/trivy-scan-results.json b/bfx/kover/trivy-scan-results.json new file mode 100644 index 00000000..618504be --- /dev/null +++ b/bfx/kover/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "kover", + "scan_timestamp": "2026-08-16T17:09:48Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/krakentools/trivy-scan-results.json b/bfx/krakentools/trivy-scan-results.json new file mode 100644 index 00000000..ee8318b8 --- /dev/null +++ b/bfx/krakentools/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "krakentools", + "scan_timestamp": "2026-08-16T17:09:49Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/lambda/trivy-scan-results.json b/bfx/lambda/trivy-scan-results.json new file mode 100644 index 00000000..10020ed6 --- /dev/null +++ b/bfx/lambda/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "lambda", + "scan_timestamp": "2026-08-16T17:09:50Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/last/trivy-scan-results.json b/bfx/last/trivy-scan-results.json new file mode 100644 index 00000000..3b776074 --- /dev/null +++ b/bfx/last/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "last", + "scan_timestamp": "2026-08-16T17:09:50Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/ldhat/trivy-scan-results.json b/bfx/ldhat/trivy-scan-results.json new file mode 100644 index 00000000..b6837055 --- /dev/null +++ b/bfx/ldhat/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "ldhat", + "scan_timestamp": "2026-08-16T17:09:51Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/ldsc/trivy-scan-results.json b/bfx/ldsc/trivy-scan-results.json new file mode 100644 index 00000000..26785cb8 --- /dev/null +++ b/bfx/ldsc/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "ldsc", + "scan_timestamp": "2026-08-16T17:09:52Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/liftoff/trivy-scan-results.json b/bfx/liftoff/trivy-scan-results.json new file mode 100644 index 00000000..0156402d --- /dev/null +++ b/bfx/liftoff/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "liftoff", + "scan_timestamp": "2026-08-16T17:09:53Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/liftofftools/trivy-scan-results.json b/bfx/liftofftools/trivy-scan-results.json new file mode 100644 index 00000000..a628efa3 --- /dev/null +++ b/bfx/liftofftools/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "liftofftools", + "scan_timestamp": "2026-08-16T17:09:54Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/lima/trivy-scan-results.json b/bfx/lima/trivy-scan-results.json new file mode 100644 index 00000000..95aba8f8 --- /dev/null +++ b/bfx/lima/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "lima", + "scan_timestamp": "2026-08-16T17:09:55Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/longphase/trivy-scan-results.json b/bfx/longphase/trivy-scan-results.json new file mode 100644 index 00000000..81134584 --- /dev/null +++ b/bfx/longphase/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "longphase", + "scan_timestamp": "2026-08-16T17:09:56Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/longqc/trivy-scan-results.json b/bfx/longqc/trivy-scan-results.json new file mode 100644 index 00000000..a0af3efd --- /dev/null +++ b/bfx/longqc/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "longqc", + "scan_timestamp": "2026-08-16T17:09:57Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/lra/trivy-scan-results.json b/bfx/lra/trivy-scan-results.json new file mode 100644 index 00000000..0698c8da --- /dev/null +++ b/bfx/lra/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "lra", + "scan_timestamp": "2026-08-16T17:09:58Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/ltr_finder/trivy-scan-results.json b/bfx/ltr_finder/trivy-scan-results.json new file mode 100644 index 00000000..8f9026f1 --- /dev/null +++ b/bfx/ltr_finder/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "ltr_finder", + "scan_timestamp": "2026-08-16T17:09:58Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/ltrpred/trivy-scan-results.json b/bfx/ltrpred/trivy-scan-results.json new file mode 100644 index 00000000..5a4534a7 --- /dev/null +++ b/bfx/ltrpred/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "ltrpred", + "scan_timestamp": "2026-08-16T17:09:59Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +} diff --git a/bfx/macrel/trivy-scan-results.json b/bfx/macrel/trivy-scan-results.json new file mode 100644 index 00000000..2347f801 --- /dev/null +++ b/bfx/macrel/trivy-scan-results.json @@ -0,0 +1,10 @@ +{ + "tool": "macrel", + "scan_timestamp": "2026-08-16T17:10:00Z", + "workflow_run_id": "31960542324", + "versions": {}, + "summary": { + "total_versions_scanned": 0, + "total_vulnerabilities": 0 + } +}