<?xml version="1.0" encoding="UTF-8"?>
  <testsuites tests="480" disabled="395" errors="0" failures="3" time="2163.344600126">
      <testsuite name="Red Hat App Studio E2E tests" package="/tmp/tmp.QN7KPSPXeP/cmd" tests="480" disabled="88" skipped="307" errors="0" failures="3" time="2163.344600126" timestamp="2026-04-22T13:50:09">
          <properties>
              <property name="SuiteSucceeded" value="false"></property>
              <property name="SuiteHasProgrammaticFocus" value="false"></property>
              <property name="SpecialSuiteFailureReason" value=""></property>
              <property name="SuiteLabels" value="[]"></property>
              <property name="SuiteSemVerConstraints" value="[]"></property>
              <property name="SuiteComponentSemVerConstraints" value="[]"></property>
              <property name="RandomSeed" value="1776864633"></property>
              <property name="RandomizeAllSpecs" value="false"></property>
              <property name="LabelFilter" value=""></property>
              <property name="SemVerFilter" value=""></property>
              <property name="FocusStrings" value=""></property>
              <property name="SkipStrings" value=""></property>
              <property name="FocusFiles" value="tests/integration-service/forgejo-integration-reporting.go;tests/integration-service/gitlab-integration-reporting.go;tests/integration-service/group-snapshots-tests.go;tests/integration-service/integration.go;tests/integration-service/status-reporting-to-pullrequest.go"></property>
              <property name="SkipFiles" value=""></property>
              <property name="FailOnPending" value="false"></property>
              <property name="FailOnEmpty" value="false"></property>
              <property name="FailFast" value="false"></property>
              <property name="FlakeAttempts" value="0"></property>
              <property name="DryRun" value="false"></property>
              <property name="ParallelTotal" value="20"></property>
              <property name="OutputInterceptorMode" value="none"></property>
          </properties>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build creates an application [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build creates an IntegrationTestScenario for the app [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build creates new branch for the build [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build creates component konflux-demo-component (private: false) from git source https://github.com/redhat-appstudio-qe/hacbs-test-project-konflux-demo [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Component is created triggers creation of a PR in the sample repo [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Component is created verifies component build status [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Component is created should eventually lead to triggering a &#39;push&#39; event type PipelineRun after merging the PaC init branch  [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun is created does not contain an annotation with a Snapshot Name [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun is created should eventually complete successfully [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should validate Tekton TaskRun test results successfully [konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should validate that the build pipelineRun is signed [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should find the related Snapshot CR [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should validate that the build pipelineRun is annotated with the name of the Snapshot [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Build PipelineRun completes successfully should find the related Integration Test PipelineRun [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when push pipelinerun is retriggered should eventually succeed [konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Integration Test PipelineRun is created should eventually complete successfully [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Integration Test PipelineRun completes successfully should lead to Snapshot CR being marked as passed [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Integration Test PipelineRun completes successfully should trigger creation of Release CR [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Release CR is created triggers creation of Release PipelineRun [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Release PipelineRun is triggered should eventually succeed [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [konflux-demo-suite] Maven project - Default build when Release PipelineRun is completed should lead to Release CR being marked as succeeded [konflux, upstream-konflux]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when a new Component with specified custom branch is created does not contain an annotation with a Snapshot Name [integration-service, github-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="54.935042243">
              <system-err>&gt; Enter [BeforeAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:45 @ 04/22/26 13:50:09.898&#xA;Build PipelineRun has not been created yet for the component stat-rep-leul/test-component-pac-ubqukc&#xA;&lt; Exit [BeforeAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:45 @ 04/22/26 13:51:04.833 (54.934s)&#xA;&gt; Enter [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:111 @ 04/22/26 13:51:04.833&#xA;&lt; Exit [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:111 @ 04/22/26 13:51:04.833 (0s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/22/26 13:51:04.833&#xA;&lt; Exit [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/22/26 13:51:04.833 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when a new Component with specified custom branch is created should have a related PaC init PR created [integration-service, github-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.274534314">
              <system-err>&gt; Enter [It] should have a related PaC init PR created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:115 @ 04/22/26 13:51:04.834&#xA;&lt; Exit [It] should have a related PaC init PR created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:115 @ 04/22/26 13:51:05.108 (274ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/22/26 13:51:05.108&#xA;&lt; Exit [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/22/26 13:51:05.108 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when a new Component with specified custom branch is created initialized integration test status is reported to github [integration-service, github-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.283050035">
              <system-err>&gt; Enter [It] initialized integration test status is reported to github - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:134 @ 04/22/26 13:51:05.109&#xA;&lt; Exit [It] initialized integration test status is reported to github - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:134 @ 04/22/26 13:51:05.391 (283ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/22/26 13:51:05.392&#xA;&lt; Exit [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/22/26 13:51:05.392 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when a new Component with specified custom branch is created should lead to build PipelineRun finishing successfully [integration-service, github-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="failed" time="321.191098736">
              <failure message="build pipelinerun fails for NameSpace/Application/Component stat-rep-leul/integ-app-gpju/test-component-pac-ubqukc with logs: Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed&#xA;&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000b89790&gt;: &#xA;    Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed&#xA;    &#xA;    {&#xA;        s: &#34;Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed\n&#34;,&#xA;    }" type="failed">[FAILED] build pipelinerun fails for NameSpace/Application/Component stat-rep-leul/integ-app-gpju/test-component-pac-ubqukc with logs: Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed&#xA;&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000b89790&gt;: &#xA;    Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed&#xA;    &#xA;    {&#xA;        s: &#34;Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed\n&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:146 @ 04/22/26 13:56:25.532&#xA;</failure>
              <system-err>&gt; Enter [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:144 @ 04/22/26 13:51:05.392&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Running&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: PipelineRunStopping&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: PipelineRunStopping&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: PipelineRunStopping&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: PipelineRunStopping&#xA;PipelineRun test-component-pac-ubqukc-on-pull-request-jsngz reason: Failed&#xA;[FAILED] build pipelinerun fails for NameSpace/Application/Component stat-rep-leul/integ-app-gpju/test-component-pac-ubqukc with logs: Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed&#xA;&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc000b89790&gt;: &#xA;    Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed&#xA;    &#xA;    {&#xA;        s: &#34;Pipelinerun &#39;test-component-pac-ubqukc-on-pull-request-jsngz&#39; didn&#39;t succeed\n&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:146 @ 04/22/26 13:56:25.532&#xA;&lt; Exit [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:144 @ 04/22/26 13:56:25.532 (5m20.139s)&#xA;&gt; Enter [AfterAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:94 @ 04/22/26 13:56:25.532&#xA;&lt; Exit [AfterAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:94 @ 04/22/26 13:56:26.454 (922ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/22/26 13:56:26.454&#xA;&lt; Exit [AfterEach] [integration-service-suite Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:42 @ 04/22/26 13:56:26.583 (129ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when the PaC build pipelineRun run succeeded checks if the BuildPipelineRun have the annotation of chains signed [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:151 @ 04/22/26 13:56:26.584&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when the PaC build pipelineRun run succeeded checks if the Snapshot is created [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:155 @ 04/22/26 13:56:26.584&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when the PaC build pipelineRun run succeeded checks if the Build PipelineRun got annotated with Snapshot name [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:160 @ 04/22/26 13:56:26.584&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when the Snapshot was created should find both the related Integration PipelineRuns [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:166 @ 04/22/26 13:56:26.585&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns are created should eventually complete successfully [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:190 @ 04/22/26 13:56:26.585&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully should lead to Snapshot CR being marked as failed [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:199 @ 04/22/26 13:56:26.585&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the successful Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:213 @ 04/22/26 13:56:26.585&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the failed Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:217 @ 04/22/26 13:56:26.586&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the optional Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:221 @ 04/22/26 13:56:26.586&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the warning Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:225 @ 04/22/26 13:56:26.586&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully checks if the optional Integration Test Scenario status is reported in the Snapshot [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:229 @ 04/22/26 13:56:26.586&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully checks if the finalizer was removed from the optional Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:244 @ 04/22/26 13:56:26.587&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully checks if the warning Integration Test Scenario status is reported in the Snapshot [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:248 @ 04/22/26 13:56:26.587&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully checks if the finalizer was removed from the warning Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:263 @ 04/22/26 13:56:26.587&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully merging the PR, expected to succeed  [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:267 @ 04/22/26 13:56:26.587&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully leads to triggering a push PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:276 @ 04/22/26 13:56:26.588&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully verifies that Push PipelineRuns completed [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:291 @ 04/22/26 13:56:26.588&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully validates the Integration test scenario PipelineRun is reported to merge request CheckRuns, and it pass [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:297 @ 04/22/26 13:56:26.588&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when Integration PipelineRuns completes successfully eventually leads to the status reported at Checks tab for the failed Integration PipelineRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:302 @ 04/22/26 13:56:26.588&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when The git-provider annotation is missing should set the git-reporting-failure annotation correctly [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:308 @ 04/22/26 13:56:26.588&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when build pipelinerun fails build pipelinerun is created but fails [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:355 @ 04/22/26 13:56:26.589&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Status Reporting of Integration tests] with status reporting of Integration tests in CheckRuns when build pipelinerun fails build pipelinerun failure is reported to integration test checkRun [integration-service, github-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/status-reporting-to-pullrequest.go:400 @ 04/22/26 13:56:26.589&#xA;</system-err>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when creating tenants and running initial pipelines should create both tenants concurrently [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when creating tenants and running initial pipelines should wait for all build PipelineRuns to succeed [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when backing up tenant data should create backup CRs for both tenants concurrently [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when simulating disaster by deleting namespaces should delete both tenant namespaces [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when restoring from backup should restore tenant-1 (KokoHazamar) via velero CLI method [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when restoring from backup should restore tenant-2 (MosheKipod) via oc command method [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when performing post-restore recovery should rotate SA tokens on both tenants [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when verifying restored tenants should confirm structural integrity of both tenants [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Same-Version Backup/Restore] when verifying restored tenants should confirm functional pipeline execution after restore [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when creating tenants on the old Konflux version should create both tenants concurrently [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when creating tenants on the old Konflux version should wait for all build PipelineRuns to succeed [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when backing up tenant data before upgrade should create backup CRs for both tenants concurrently [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when simulating disaster by deleting namespaces should delete both tenant namespaces [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when upgrading Konflux to the new version should upgrade the cluster and verify Velero survived [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when restoring tenants from backup on the new Konflux version should restore tenant-1 (KokoHazamar) via velero CLI method [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when restoring tenants from backup on the new Konflux version should restore tenant-2 (MosheKipod) via oc command method [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when performing post-restore recovery should rotate SA tokens on both tenants [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when verifying restored tenants should confirm structural integrity of both tenants [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [disaster-recovery DR Backwards-Compat] when verifying restored tenants should confirm functional pipeline execution after restore [disaster-recovery, Serial]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-advisories pipeline] Rh-advisories happy path Post-release verification verifies if release CR is created [release-pipelines, rh-advisories, rhAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-advisories pipeline] Rh-advisories happy path Post-release verification verifies the advs release pipelinerun is running and succeeds [release-pipelines, rh-advisories, rhAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-advisories pipeline] Rh-advisories happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, rh-advisories, rhAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-advisories pipeline] Rh-advisories happy path Post-release verification verifies if the repository URL is valid [release-pipelines, rh-advisories, rhAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for multi arch with rh-advisories pipeline] Multi arch test happy path Post-release verification verifies the release CR is created [release-pipelines, rh-advisories, multiarch-advisories, multiArchAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for multi arch with rh-advisories pipeline] Multi arch test happy path Post-release verification verifies the multiarch release pipelinerun is running and succeeds [release-pipelines, rh-advisories, multiarch-advisories, multiArchAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for multi arch with rh-advisories pipeline] Multi arch test happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, rh-advisories, multiarch-advisories, multiArchAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for multi arch with rh-advisories pipeline] Multi arch test happy path Post-release verification verifies if the repository URL is valid [release-pipelines, rh-advisories, multiarch-advisories, multiArchAdvisories]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params when context points to a file [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params creates Tekton bundles from specific context [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params when context is the root directory [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params creates Tekton bundles when context points to a file and a directory [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params creates Tekton bundles when using negation [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params allows overriding HOME environment variable [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [task-suite tkn bundle task] creates Tekton bundles with different params allows overriding STEP image [build-templates]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created a PipelineRun is triggered [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created the build-container task from component pipelinerun is buildah-remote [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created The multi platform secret is populated [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created that PipelineRun completes successfully [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws host-pool allocation when the Component with multi-platform-build is created test that cleanup happened successfully [multi-platform, aws-host-pool]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created a PipelineRun is triggered [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created the build-container task from component pipelinerun is buildah-remote [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created The multi platform secret is populated [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created that PipelineRun completes successfully [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] aws dynamic allocation when the Component with multi-platform-build is created check cleanup happened successfully [multi-platform, aws-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created a PipelineRun is triggered [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created the build-container task from component pipelinerun is buildah-remote [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created The multi platform secret is populated [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created that PipelineRun completes successfully [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm system z dynamic allocation when the Component with multi-platform-build is created check cleanup happened successfully [multi-platform, ibmz-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created a PipelineRun is triggered [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created the build-container task from component pipelinerun is buildah-remote [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created The multi platform secret is populated [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created that PipelineRun completes successfully [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [multi-platform-build-service-suite Multi Platform Controller E2E tests] ibm power pc dynamic allocation when the Component with multi-platform-build is created check cleanup happened successfully [multi-platform, ibmp-dynamic]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace creates component with nudges [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace triggers a PipelineRun for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace should lead to a PaC PR creation for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace Merging the PaC PR should be successful for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace create dockerfile and yaml manifest that references build and distribution repositories [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace should lead to a PaC PR creation for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace Merging the PaC PR should be successful for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace PR merge triggers PAC PipelineRun for parent component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace PAC PipelineRun for parent component  is successful [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace should lead to a nudge PR creation for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace merging the PR should be successful for child component  [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl component update with renovate when components are created in same namespace Verify the nudge updated the contents [build-service, renovate, multi-component, gitlab]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite Push to external registry] Post-release verification verifies that a Release CR should have been created in the dev namespace [release-pipelines, push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite Push to external registry] Post-release verification verifies that Release PipelineRun should eventually succeed [release-pipelines, push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite Push to external registry] Post-release verification tests if the image was pushed to quay [release-pipelines, push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite Push to external registry] Post-release verification verifies that a Release is marked as succeeded. [release-pipelines, push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite Release service tenant pipeline] Post-release verification verifies that a Release CR should have been created in the dev namespace [release-service, tenant]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite Release service tenant pipeline] Post-release verification verifies that Tenant PipelineRun is triggered [release-service, tenant]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite Release service tenant pipeline] Post-release verification verifies that a Release is marked as succeeded. [release-service, tenant]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build annotations when component is created with invalid build request annotations handles invalid request annotation [build-service, github, annotations]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace creates component with nudges [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace triggers a PipelineRun for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace should lead to a PaC PR creation for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace Merging the PaC PR should be successful for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace create dockerfile and yaml manifest that references build and distribution repositories [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace should lead to a PaC PR creation for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace Merging the PaC PR should be successful for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace PR merge triggers PAC PipelineRun for parent component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace PAC PipelineRun for parent component  is successful [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace should lead to a nudge PR creation for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace merging the PR should be successful for child component  [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj component update with renovate when components are created in same namespace Verify the nudge updated the contents [build-service, renovate, multi-component, forgejo]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite [RELEASE-2136] Release CR fails when block-releases true in ReleasePlanAdmission.] post-release verification. block-releases true in ReleasePlanAdmission makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. [release-service, release-neg, negBlockReleases]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [upgrade-suite Create users and check their state] Verify AppStudioProvisionedUser [upgrade-verify]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [upgrade-suite Create users and check their state] creates AppStudioDeactivatedUser [upgrade-verify]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [upgrade-suite Create users and check their state] creates AppStudioBannedUser [upgrade-verify]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for release-to-github pipeline] Release-to-github happy path Post-release verification verifies if release CR is created [release-pipelines, release-to-github, releaseToGithub]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for release-to-github pipeline] Release-to-github happy path Post-release verification verifies the release pipelinerun is running and succeeds [release-pipelines, release-to-github, releaseToGithub]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for release-to-github pipeline] Release-to-github happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, release-to-github, releaseToGithub]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for release-to-github pipeline] Release-to-github happy path Post-release verification verifies if the Release exists in github repo [release-pipelines, release-to-github, releaseToGithub]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace creates component with nudges [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace triggers a PipelineRun for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace the PipelineRun should eventually finish successfully for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace should lead to a PaC PR creation for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace Merging the PaC PR should be successful for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace create dockerfile and yaml manifest that references build and distribution repositories [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace should lead to a PaC PR creation for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace Merging the PaC PR should be successful for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace PR merge triggers PAC PipelineRun for parent component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace PAC PipelineRun for parent component  is successful [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace should lead to a nudge PR creation for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace merging the PR should be successful for child component  [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh component update with renovate when components are created in same namespace Verify the nudge updated the contents [build-service, renovate, multi-component, github]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created creates first component [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created creates second component [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created check first component annotation has errors [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created triggered PipelineRun is for component  [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created check only one pipelinerun should be triggered [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test build secret lookup when two secrets are created when second component is deleted, pac pr branch should not exist in the repo [build-service, github, pac-build, secret-lookup]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rhtap-service-push pipeline] Rhtap-service-push happy path Post-release verification verifies if the release CR is created [release-pipelines, rhtap-service-push, RhtapServicePush]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rhtap-service-push pipeline] Rhtap-service-push happy path Post-release verification verifies the rhtap release pipelinerun is running and succeeds [release-pipelines, rhtap-service-push, RhtapServicePush]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rhtap-service-push pipeline] Rhtap-service-push happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, rhtap-service-push, RhtapServicePush]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rhtap-service-push pipeline] Rhtap-service-push happy path Post-release verification verifies if the PR in infra-deployments repo is created/updated [release-pipelines, rhtap-service-push, RhtapServicePush]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace creates component with context directory go-component [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace triggers a PipelineRun for component go-component-dsorpp [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace should lead to a PaC PR creation for component go-component-dsorpp [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace the PipelineRun should eventually finish successfully for component go-component-dsorpp [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace merging the PR should be successful [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace leads to triggering on push PipelineRun [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace creates component with context directory python-component [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace triggers a PipelineRun for component python-component-epjjhv [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace should lead to a PaC PR creation for component python-component-epjjhv [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace the PipelineRun should eventually finish successfully for component python-component-epjjhv [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace merging the PR should be successful [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace leads to triggering on push PipelineRun [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace only one component is changed [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when components are created in same namespace only related pipelinerun should be triggered [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test pac with multiple components using same repository when a components is created with same git url in different namespace should fail to configure PaC for the component [build-service, github, pac-build, multi-component]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] infrastructure is running verifies if the chains controller is running [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] infrastructure is running verifies the signing secret is present [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task creates signature and attestation [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task succeeds when policy is met [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task does not pass when tests are not satisfied on non-strict mode [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task fails when tests are not satisfied on strict mode [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task fails when unexpected signature is used [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task ec-cli command verifies ec cli has error handling [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task ec-cli command verifies ec validate accepts a list of image references [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task Release Policy verifies redhat products pass the redhat policy rule collection before release  [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task Release Policy verifies the release policy: Task are trusted [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [enterprise-contract-suite Conforma E2E tests] test creating and signing an image and task verify-enterprise-contract task Release Policy verifies the release policy: Task references are pinned [ec, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC happy path Post-release verification creates component from git source https://github.com/redhat-appstudio-qe/fbc-sample-repo-test [release-pipelines, fbc-release, fbcHappyPath]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC happy path Post-release verification Creates a push snapshot for a release [release-pipelines, fbc-release, fbcHappyPath]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC happy path Post-release verification verifies the fbc release pipelinerun is running and succeeds [release-pipelines, fbc-release, fbcHappyPath]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, fbc-release, fbcHappyPath]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC Staged Index Post-release verification creates component from git source https://github.com/redhat-appstudio-qe/fbc-sample-repo-test [release-pipelines, fbc-release, fbcStagedIndex]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC Staged Index Post-release verification Creates a push snapshot for a release [release-pipelines, fbc-release, fbcStagedIndex]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC Staged Index Post-release verification verifies the fbc release pipelinerun is running and succeeds [release-pipelines, fbc-release, fbcStagedIndex]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC Staged Index Post-release verification verifies release CR completed and set succeeded. [release-pipelines, fbc-release, fbcStagedIndex]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC hotfix process FBC hotfix post-release verification creates component from git source https://github.com/redhat-appstudio-qe/fbc-sample-repo-test [release-pipelines, fbc-release, fbcHotfix]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC hotfix process FBC hotfix post-release verification Creates a push snapshot for a release [release-pipelines, fbc-release, fbcHotfix]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC hotfix process FBC hotfix post-release verification verifies the fbc release pipelinerun is running and succeeds [release-pipelines, fbc-release, fbcHotfix]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC hotfix process FBC hotfix post-release verification verifies release CR completed and set succeeded. [release-pipelines, fbc-release, fbcHotfix]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC pre-GA process FBC pre-GA post-release verification creates component from git source https://github.com/redhat-appstudio-qe/fbc-sample-repo-test [release-pipelines, fbc-release, fbcPreGA]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC pre-GA process FBC pre-GA post-release verification Creates a push snapshot for a release [release-pipelines, fbc-release, fbcPreGA]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC pre-GA process FBC pre-GA post-release verification verifies the fbc release pipelinerun is running and succeeds [release-pipelines, fbc-release, fbcPreGA]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite FBC e2e-tests] with FBC pre-GA process FBC pre-GA post-release verification verifies release CR completed and set succeeded. [release-pipelines, fbc-release, fbcPreGA]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private correctly targets the default branch (that is not named &#39;main&#39;) with PaC [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private workspace parameter is set correctly in PaC repository CR [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private build pipeline uses the correct serviceAccount [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private component build status is set correctly [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private created image repo is private [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private a related PipelineRun should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private PR branch should not exist in the repo [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new component without specified branch is created and with visibility private related image repo and the robot account should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, github, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created should lead to a PaC init PR creation [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created created image repo is public [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created image tag is updated successfully [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created should ensure pruning labels are set [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when a new Component with specified custom branch is created eventually leads to the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is updated eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is updated should lead to a PaC init PR update [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is updated PipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is updated eventually leads to another update of a PR about the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged does not have expiration set [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged After updating image visibility to private, it should not trigger another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged image repo is updated to private [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged retrigger the pipeline manually [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the PaC init branch is merged retriggered pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gh PaC component build when the component is removed and recreated (with the same name in the same namespace) should no longer lead to a creation of a PaC PR [build-service, github-webhook, pac-build, pipeline, image-controller, github, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite Release service happy path] Post-release verification verifies that a Release CR should have been created in the dev namespace [release-service, happy-path]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite Release service happy path] Post-release verification verifies that Release PipelineRun is triggered [release-service, happy-path]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite Release service happy path] Post-release verification verifies that Enterprise Contract Task has succeeded in the Release PipelineRun [release-service, happy-path]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite Release service happy path] Post-release verification verifies that a Release is marked as succeeded. [release-service, happy-path]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-push-to-redhat-io pipeline] Rh-push-to-redhat-io happy path Post-release verification verifies if the release CR is created [release-pipelines, rh-push-to-registry-redhat-io, PushToRedhatIO]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-push-to-redhat-io pipeline] Rh-push-to-redhat-io happy path Post-release verification verifies the rhio release pipelinerun is running and succeeds [release-pipelines, rh-push-to-registry-redhat-io, PushToRedhatIO]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-push-to-redhat-io pipeline] Rh-push-to-redhat-io happy path Post-release verification verifies release CR completed and set succeeded. [release-pipelines, rh-push-to-registry-redhat-io, PushToRedhatIO]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite e2e tests for rh-push-to-redhat-io pipeline] Rh-push-to-redhat-io happy path Post-release verification verifies if the MR URL is valid [release-pipelines, rh-push-to-registry-redhat-io, PushToRedhatIO]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private correctly targets the default branch (that is not named &#39;main&#39;) with PaC [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private workspace parameter is set correctly in PaC repository CR [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private build pipeline uses the correct serviceAccount [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private component build status is set correctly [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private created image repo is private [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private a related PipelineRun should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private PR branch should not exist in the repo [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new component without specified branch is created and with visibility private related image repo and the robot account should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created should lead to a PaC init PR creation [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created created image repo is public [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created image tag is updated successfully [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created should ensure pruning labels are set [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when a new Component with specified custom branch is created eventually leads to the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is updated eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is updated should lead to a PaC init PR update [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is updated PipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is updated eventually leads to another update of a PR about the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged does not have expiration set [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged After updating image visibility to private, it should not trigger another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged image repo is updated to private [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged retrigger the pipeline manually [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the PaC init branch is merged retriggered pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider fj PaC component build when the component is removed and recreated (with the same name in the same namespace) should no longer lead to a creation of a PaC PR [build-service, github-webhook, pac-build, pipeline, image-controller, forgejo, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification tests that Release CR is created for the Snapshot [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification verifies a release PipelineRun is started and succeeded in managed namespace [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification validate the result of task create-pyxis-image contains image ids [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification tests that Release CR has completed [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [release-pipelines-suite [HACBS-1571]test-release-e2e-push-image-to-pyxis] Post-release verification validates that imageIds from task create-pyxis-image exist in Pyxis. [release-pipelines, rh-push-to-external-registry]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines triggers PipelineRun for symlink component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic with component name test-symlink-comp-arax [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci triggers PipelineRun for component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci triggers PipelineRun for component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci triggers PipelineRun for component with source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) should eventually finish successfully for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) should push Dockerfile to registry [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) floating tags are created successfully [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) image manifest mediaType is correct [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) check for source images if enabled in pipeline [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min should have Pipeline Records [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min should have Pipeline Logs [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) should validate tekton taskrun test results for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta-min [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry verify-enterprise-contract check should pass [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry should have Hermeto content in the SBOM in case the build was hermetic [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta-min) build-definitions ec pipelines runs ec pipeline pipelines/enterprise-contract.yaml [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) should eventually finish successfully for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) should push Dockerfile to registry [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) floating tags are created successfully [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) image manifest mediaType is correct [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) check for source images if enabled in pipeline [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build should have Pipeline Records [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build should have Pipeline Logs [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) should validate tekton taskrun test results for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry verify-enterprise-contract check should pass [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry should have Hermeto content in the SBOM in case the build was hermetic [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build) build-definitions ec pipelines runs ec pipeline pipelines/enterprise-contract.yaml [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) should eventually finish successfully for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) should push Dockerfile to registry [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) floating tags are created successfully [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) image manifest mediaType is correct [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) check for source images if enabled in pipeline [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta should have Pipeline Records [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) when Pipeline Results are stored for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta should have Pipeline Logs [build, build-templates, HACBS, pipeline-service, pipeline]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) should validate tekton taskrun test results for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic and Pipeline docker-build-oci-ta [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry verify-enterprise-contract check should pass [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) when the container image for component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic is created and pushed to container registry should have Hermeto content in the SBOM in case the build was hermetic [build, build-templates, HACBS, pipeline-service, pipeline, sbom, slow, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines scenario sample-python-basic-oci (docker-build-oci-ta) build-definitions ec pipelines runs ec pipeline pipelines/enterprise-contract.yaml [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build templates E2E test] HACBS pipelines pipelineRun should fail for symlink component with Git source URL https://github.com/redhat-appstudio-qe/devfile-sample-python-basic with component name test-symlink-comp-arax [build, build-templates, HACBS, pipeline-service, pipeline, build-templates-e2e, source-build-e2e]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] post-release verification. missing ReleasePlan makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. [release-service, release-neg, negMissingReleasePlan]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite [HACBS-2360] Release CR fails when missing ReleasePlan and ReleasePlanAdmission.] post-release verification. missing ReleasePlanAdmission makes a Release CR set as failed in both IsReleased and IsValid with a proper message to user. [release-service, release-neg, negMissingReleasePlan]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private correctly targets the default branch (that is not named &#39;main&#39;) with PaC [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private workspace parameter is set correctly in PaC repository CR [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private build pipeline uses the correct serviceAccount [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private component build status is set correctly [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private created image repo is private [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private a related PipelineRun should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private PR branch should not exist in the repo [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new component without specified branch is created and with visibility private related image repo and the robot account should be deleted after deleting the component [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, pac-custom-default-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created triggers a PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created should lead to a PaC init PR creation [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created image repo and robot account created successfully [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created created image repo is public [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created image tag is updated successfully [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created should ensure pruning labels are set [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when a new Component with specified custom branch is created eventually leads to the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is updated eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is updated should lead to a PaC init PR update [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is updated PipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is updated eventually leads to another update of a PR about the PipelineRun status report at Checks tab [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged eventually leads to triggering another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged does not have expiration set [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged After updating image visibility to private, it should not trigger another PipelineRun [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged image repo is updated to private [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged retrigger the pipeline manually [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the PaC init branch is merged retriggered pipelineRun should eventually finish [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="pending" time="0">
              <skipped message="pending"></skipped>
          </testcase>
          <testcase name="[It] [build-service-suite Build service E2E tests] test git provider gl PaC component build when the component is removed and recreated (with the same name in the same namespace) should no longer lead to a creation of a PaC PR [build-service, github-webhook, pac-build, pipeline, image-controller, gitlab, build-custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification verifies that the ReleasePlan CR is unmatched in the beginning [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification Creates ReleasePlanAdmission CR in corresponding managed namespace [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when ReleasePlanAdmission CR is created in managed namespace verifies that the ReleasePlan CR is set to matched [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when ReleasePlanAdmission CR is created in managed namespace verifies that the ReleasePlanAdmission CR is set to matched [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification Creates a manual release ReleasePlan CR in devNamespace [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when the second ReleasePlan CR is created verifies that the second ReleasePlan CR is set to matched [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when the second ReleasePlan CR is created verifies that the ReleasePlanAdmission CR has two matched ReleasePlan CRs [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification deletes one ReleasePlan CR [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when One ReleasePlan CR is deleted in managed namespace verifies that the ReleasePlanAdmission CR has only one matching ReleasePlan [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification deletes the ReleasePlanAdmission CR [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [release-service-suite ReleasePlan and ReleasePlanAdmission match] RP and PRA status change verification when ReleasePlanAdmission CR is deleted in managed namespace verifies that the ReleasePlan CR has no matched ReleasePlanAdmission [release-service, release_plan_and_admission]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped"></skipped>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when a new Component is created triggers a build PipelineRun [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="46.898951923">
              <system-err>&gt; Enter [BeforeAll] with happy path for general flow of Integration service - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:52 @ 04/22/26 13:50:09.899&#xA;Image repository for component test-component-pac-jfjqoi in namespace integration1-fgqi do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [BeforeAll] with happy path for general flow of Integration service - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:52 @ 04/22/26 13:50:36.778 (26.88s)&#xA;&gt; Enter [It] triggers a build PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:85 @ 04/22/26 13:50:36.778&#xA;no pipelinerun found for component test-component-pac-jfjqoi (application: integ-app-iodn, namespace: integration1-fgqi)&#xA;&lt; Exit [It] triggers a build PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:85 @ 04/22/26 13:50:56.797 (20.019s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 13:50:56.797&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 13:50:56.797 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when a new Component is created verifies if the build PipelineRun contains the finalizer [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.094813121">
              <system-err>&gt; Enter [It] verifies if the build PipelineRun contains the finalizer - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:90 @ 04/22/26 13:50:56.798&#xA;&lt; Exit [It] verifies if the build PipelineRun contains the finalizer - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:90 @ 04/22/26 13:50:56.892 (95ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 13:50:56.892&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 13:50:56.892 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when a new Component is created waits for build PipelineRun to succeed [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="573.269672497">
              <system-err>&gt; Enter [It] waits for build PipelineRun to succeed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:101 @ 04/22/26 13:50:56.893&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m found for Component integration1-fgqi/test-component-pac-jfjqoi&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: PipelineRunStopping&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: PipelineRunStopping&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: PipelineRunStopping&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-pdc9m reason: Failed&#xA;attempt 1/3: PipelineRun &#34;test-component-pac-jfjqoi-on-pull-request-pdc9m&#34; failed: &#xA; pod: test-component-pac-jfjqoi-o4e2cd86c2ab750e41ed46d6fce58adf9-pod | init container: prepare&#xA;2026/04/22 13:54:59 Entrypoint initialization&#xA;&#xA; pod: test-component-pac-jfjqoi-o4e2cd86c2ab750e41ed46d6fce58adf9-pod | init container: working-dir-initializer&#xA;&#xA;pod: test-component-pac-jfjqoi-o4e2cd86c2ab750e41ed46d6fce58adf9-pod | container step-push: &#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] image-url: quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#34;&#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] image-digest: sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138&#34;&#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] containerfile: Dockerfile&#34;&#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] context: .&#34;&#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] tag-suffix: .dockerfile&#34;&#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] artifact-type: application/vnd.konflux.dockerfile&#34;&#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] source: source&#34;&#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] result-path-image-ref: /tekton/results/IMAGE_REF&#34;&#xA;time=&#34;2026-04-22T13:55:03Z&#34; level=info msg=&#34;[param] alternative-filename: Dockerfile&#34;&#xA;time=&#34;2026-04-22T13:55:04Z&#34; level=info msg=&#34;oras [stdout] quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi@sha256:431dcc63d935a0a14c23b30c2152964f622185c61d3c4a109792badb76bbe9e5&#34; logger=CliExecutor&#xA;time=&#34;2026-04-22T13:55:04Z&#34; level=info msg=&#34;Containerfile &#39;/workspace/workspace/source/Dockerfile&#39; is pushed to registry with tag: sha256-01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138.dockerfile&#34;&#xA;{&#34;image_ref&#34;:&#34;quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi@sha256:431dcc63d935a0a14c23b30c2152964f622185c61d3c4a109792badb76bbe9e5&#34;}&#xA; pod: test-component-pac-jfjqoi-oa38676172f02acd124d987e118703e7f-pod | init container: prepare&#xA;2026/04/22 13:54:39 Entrypoint initialization&#xA;&#xA; pod: test-component-pac-jfjqoi-oa38676172f02acd124d987e118703e7f-pod | init container: place-scripts&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-0-w82q5&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-1-8q2w6&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-2-9tw8x&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-3-jmftg&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-4-gdlkw&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-5-5cltz&#xA;&#xA;pod: test-component-pac-jfjqoi-oa38676172f02acd124d987e118703e7f-pod | container step-introspect: &#xA;Artifact type will be determined by introspection.&#xA;Checking the media type of the OCI artifact...&#xA;[retry] executing: skopeo inspect --raw --retry-times 3 docker://quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;The media type of the OCI artifact is application/vnd.docker.distribution.manifest.v2+json.&#xA;Looking for image labels that indicate this might be an operator bundle...&#xA;[retry] executing: skopeo inspect --retry-times 3 docker://quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;Found 0 matching labels.&#xA;Expecting 3 or more to identify this image as an operator bundle.&#xA;Introspection concludes that this artifact is of type &#34;application&#34;.&#xA;&#xA;pod: test-component-pac-jfjqoi-oa38676172f02acd124d987e118703e7f-pod | container step-generate-container-auth: &#xA;Selecting auth for quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;Using token for quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi&#xA;Auth json written to &#34;/auth/auth.json&#34;.&#xA;&#xA;pod: test-component-pac-jfjqoi-oa38676172f02acd124d987e118703e7f-pod | container step-set-skip-for-bundles: &#xA;2026/04/22 13:56:17 INFO Step was skipped due to when expressions were evaluated to false.&#xA;&#xA;pod: test-component-pac-jfjqoi-oa38676172f02acd124d987e118703e7f-pod | container step-app-check: &#xA;time=&#34;2026-04-22T13:56:17Z&#34; level=info msg=&#34;certification library version&#34; version=&#34;1.17.1 &lt;commit: f7de82ae1c76e6c10ea94967d6b6a66f96248cbe&gt;&#34;&#xA;time=&#34;2026-04-22T13:56:18Z&#34; level=info msg=&#34;running checks for quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118 for platform amd64&#34;&#xA;time=&#34;2026-04-22T13:56:18Z&#34; level=info msg=&#34;target image&#34; image=&#34;quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#34;&#xA;time=&#34;2026-04-22T13:56:25Z&#34; level=info msg=&#34;warning: licenses directory does not exist or all of its children are empty directories: error when checking for /licenses: stat /tmp/preflight-1262972447/fs/licenses: no such file or directory&#34; check=HasLicense&#xA;time=&#34;2026-04-22T13:56:25Z&#34; level=info msg=&#34;check completed&#34; check=HasLicense result=FAILED&#xA;time=&#34;2026-04-22T13:56:25Z&#34; level=info msg=&#34;check completed&#34; check=HasUniqueTag result=PASSED&#xA;time=&#34;2026-04-22T13:56:25Z&#34; level=info msg=&#34;check completed&#34; check=LayerCountAcceptable result=PASSED&#xA;time=&#34;2026-04-22T13:56:25Z&#34; level=info msg=&#34;check completed&#34; check=HasNoProhibitedPackages result=PASSED&#xA;time=&#34;2026-04-22T13:56:25Z&#34; level=info msg=&#34;check completed&#34; check=HasRequiredLabel result=PASSED&#xA;time=&#34;2026-04-22T13:56:25Z&#34; level=info msg=&#34;USER 185 specified that is non-root&#34; check=RunAsNonRoot&#xA;time=&#34;2026-04-22T13:56:25Z&#34; level=info msg=&#34;check completed&#34; check=RunAsNonRoot result=PASSED&#xA;time=&#34;2026-04-22T13:56:34Z&#34; level=info msg=&#34;check completed&#34; check=HasModifiedFiles result=PASSED&#xA;time=&#34;2026-04-22T13:56:35Z&#34; level=info msg=&#34;check completed&#34; check=BasedOnUbi result=PASSED&#xA;time=&#34;2026-04-22T13:56:35Z&#34; level=info msg=&#34;This image&#39;s tag on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118 will be paired with digest sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138 once this image has been published in accordance with Red Hat Certification policy. You may then add or remove any supplemental tags through your Red Hat Connect portal as you see fit.&#34;&#xA;{&#xA;    &#34;image&#34;: &#34;quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#34;,&#xA;    &#34;passed&#34;: false,&#xA;    &#34;test_library&#34;: {&#xA;        &#34;name&#34;: &#34;github.com/redhat-openshift-ecosystem/openshift-preflight&#34;,&#xA;        &#34;version&#34;: &#34;1.17.1&#34;,&#xA;        &#34;commit&#34;: &#34;f7de82ae1c76e6c10ea94967d6b6a66f96248cbe&#34;&#xA;    },&#xA;    &#34;results&#34;: {&#xA;        &#34;passed&#34;: [&#xA;            {&#xA;                &#34;name&#34;: &#34;HasUniqueTag&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if container has a tag other than &#39;latest&#39;, so that the image can be uniquely identified.&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;LayerCountAcceptable&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if container has less than 40 layers.  Too many layers within the container images can degrade container performance.&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;HasNoProhibitedPackages&#34;,&#xA;                &#34;elapsed_time&#34;: 44,&#xA;                &#34;description&#34;: &#34;Checks to ensure that the image in use does not include prohibited packages, such as Red Hat Enterprise Linux (RHEL) kernel packages.&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;HasRequiredLabel&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if the required labels (name, vendor, version, release, summary, description, maintainer) are present in the container metadata&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;RunAsNonRoot&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if container runs as the root user because a container that does not specify a non-root user will fail the automatic certification, and will be subject to a manual review before the container can be approved for publication&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;HasModifiedFiles&#34;,&#xA;                &#34;elapsed_time&#34;: 8893,&#xA;                &#34;description&#34;: &#34;Checks that no files installed via RPM in the base Red Hat layer have been modified&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;BasedOnUbi&#34;,&#xA;                &#34;elapsed_time&#34;: 201,&#xA;                &#34;description&#34;: &#34;Checking if the container&#39;s base image is based upon the Red Hat Universal Base Image (UBI)&#34;&#xA;            }&#xA;        ],&#xA;        &#34;failed&#34;: [&#xA;            {&#xA;                &#34;name&#34;: &#34;HasLicense&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if terms and conditions applicable to the software including open source licensing information are present. The license must be at /licenses&#34;,&#xA;                &#34;help&#34;: &#34;Check HasLicense encountered an error. Please review the preflight.log file for more information.&#34;,&#xA;                &#34;suggestion&#34;: &#34;Create a directory named /licenses and include all relevant licensing and/or terms and conditions as text file(s) in that directory.&#34;,&#xA;                &#34;knowledgebase_url&#34;: &#34;https://access.redhat.com/documentation/en-us/red_hat_software_certification/2024/html-single/red_hat_openshift_software_certification_policy_guide/index#assembly-requirements-for-container-images_openshift-sw-cert-policy-introduction&#34;,&#xA;                &#34;check_url&#34;: &#34;https://access.redhat.com/documentation/en-us/red_hat_software_certification/2024/html-single/red_hat_openshift_software_certification_policy_guide/index#assembly-requirements-for-container-images_openshift-sw-cert-policy-introduction&#34;&#xA;            }&#xA;        ],&#xA;        &#34;errors&#34;: []&#xA;    }&#xA;}&#xA;time=&#34;2026-04-22T13:56:35Z&#34; level=info msg=&#34;Preflight result: FAILED&#34;&#xA;&#xA;pod: test-component-pac-jfjqoi-oa38676172f02acd124d987e118703e7f-pod | container step-app-set-outcome: &#xA;{&#34;result&#34;:&#34;FAILURE&#34;,&#34;timestamp&#34;:&#34;1776866196&#34;,&#34;note&#34;:&#34;Task preflight is a FAILURE: Refer to Tekton task logs for more information&#34;,&#34;successes&#34;:7,&#34;failures&#34;:1,&#34;warnings&#34;:0}[retry] executing: skopeo inspect --raw --retry-times 3 docker://quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;&#xA;pod: test-component-pac-jfjqoi-oa38676172f02acd124d987e118703e7f-pod | container step-final-outcome: &#xA;+ [[ ! -f /mount/konflux.results.json ]]&#xA;+ tee /tekton/steps/step-final-outcome/results/test-output&#xA;{&#34;result&#34;:&#34;FAILURE&#34;,&#34;timestamp&#34;:&#34;1776866196&#34;,&#34;note&#34;:&#34;Task preflight is a FAILURE: Refer to Tekton task logs for more information&#34;,&#34;successes&#34;:7,&#34;failures&#34;:1,&#34;warnings&#34;:0}&#xA; pod: test-component-pac-jfjqoi-ob4259b147a08930b3126dc25f096f4e6-pod | init container: prepare&#xA;2026/04/22 13:51:40 Entrypoint initialization&#xA;&#xA; pod: test-component-pac-jfjqoi-ob4259b147a08930b3126dc25f096f4e6-pod | init container: place-scripts&#xA;2026/04/22 13:51:41 Decoded script /tekton/scripts/script-0-7djs4&#xA;2026/04/22 13:51:41 Decoded script /tekton/scripts/script-1-7x972&#xA;2026/04/22 13:51:41 Decoded script /tekton/scripts/script-2-9ks4h&#xA;2026/04/22 13:51:41 Decoded script /tekton/scripts/script-3-xbkr7&#xA;2026/04/22 13:51:41 Decoded script /tekton/scripts/script-4-k6jq5&#xA;&#xA; pod: test-component-pac-jfjqoi-ob4259b147a08930b3126dc25f096f4e6-pod | init container: working-dir-initializer&#xA;&#xA;pod: test-component-pac-jfjqoi-ob4259b147a08930b3126dc25f096f4e6-pod | container step-build: &#xA;[2026-04-22T13:52:17,572641346+00:00] Validate context path&#xA;[2026-04-22T13:52:17,575882742+00:00] Update CA trust&#xA;[2026-04-22T13:52:17,576968401+00:00] Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;[2026-04-22T13:52:19,638909850+00:00] Prepare Dockerfile&#xA;Checking if /var/workdir/cachi2/output/bom.json exists.&#xA;Could not find prefetched sbom. No content_sets found for ICM&#xA;[2026-04-22T13:52:19,644610446+00:00] Prepare system (architecture: x86_64)&#xA;[2026-04-22T13:52:19,671195012+00:00] Setup prefetched&#xA;Trying to pull registry.access.redhat.com/ubi8/openjdk-17-runtime:1.23...&#xA;Getting image source signatures&#xA;Checking if image destination supports signatures&#xA;Copying blob sha256:e2e03c29fb52977524b66e25d9363bc1813d154483d05951cf28aeb7ea0ae603&#xA;Copying blob sha256:d048357fb75839f8d54c470c087c578ad01acd0b0438c09ce513782902b26870&#xA;Copying config sha256:e282c638a3ca476e76e9a02b5219b1fb2354beb4244ba48db14e554e49420569&#xA;Writing manifest to image destination&#xA;Storing signatures&#xA;[2026-04-22T13:52:55,081858379+00:00] Unsetting proxy&#xA;{&#xA;  &#34;architecture&#34;: &#34;x86_64&#34;,&#xA;  &#34;build-date&#34;: &#34;2026-04-22T13:52:19Z&#34;,&#xA;  &#34;com.redhat.component&#34;: &#34;openjdk-17-runtime-ubi8-container&#34;,&#xA;  &#34;com.redhat.license_terms&#34;: &#34;https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI&#34;,&#xA;  &#34;cpe&#34;: &#34;cpe:/a:redhat:enterprise_linux:8::appstream&#34;,&#xA;  &#34;description&#34;: &#34;Image for Red Hat OpenShift providing OpenJDK 17 runtime&#34;,&#xA;  &#34;distribution-scope&#34;: &#34;public&#34;,&#xA;  &#34;io.buildah.version&#34;: &#34;1.42.2&#34;,&#xA;  &#34;io.cekit.version&#34;: &#34;4.13.0.dev0&#34;,&#xA;  &#34;io.k8s.description&#34;: &#34;Platform for running plain Java applications (fat-jar and flat classpath)&#34;,&#xA;  &#34;io.k8s.display-name&#34;: &#34;Java Applications&#34;,&#xA;  &#34;io.openshift.expose-services&#34;: &#34;&#34;,&#xA;  &#34;io.openshift.tags&#34;: &#34;java&#34;,&#xA;  &#34;maintainer&#34;: &#34;Red Hat OpenJDK &lt;openjdk@redhat.com&gt;&#34;,&#xA;  &#34;name&#34;: &#34;ubi8/openjdk-17-runtime&#34;,&#xA;  &#34;org.jboss.product&#34;: &#34;openjdk&#34;,&#xA;  &#34;org.jboss.product.openjdk.version&#34;: &#34;17&#34;,&#xA;  &#34;org.jboss.product.version&#34;: &#34;17&#34;,&#xA;  &#34;org.opencontainers.image.created&#34;: &#34;2026-04-22T13:52:19Z&#34;,&#xA;  &#34;org.opencontainers.image.documentation&#34;: &#34;https://rh-openjdk.github.io/redhat-openjdk-containers/&#34;,&#xA;  &#34;org.opencontainers.image.revision&#34;: &#34;ed3328a539acc00b4d626fb0525fc3656cfad118&#34;,&#xA;  &#34;release&#34;: &#34;4.1776364351&#34;,&#xA;  &#34;summary&#34;: &#34;Image for Red Hat OpenShift providing OpenJDK 17 runtime&#34;,&#xA;  &#34;url&#34;: &#34;https://access.redhat.com/containers/#/registry.access.redhat.com/ubi8/openjdk-17-runtime/images/1.23-4.1776364351&#34;,&#xA;  &#34;usage&#34;: &#34;https://rh-openjdk.github.io/redhat-openjdk-containers/&#34;,&#xA;  &#34;vcs-ref&#34;: &#34;ed3328a539acc00b4d626fb0525fc3656cfad118&#34;,&#xA;  &#34;vcs-type&#34;: &#34;git&#34;,&#xA;  &#34;vendor&#34;: &#34;Red Hat, Inc.&#34;,&#xA;  &#34;version&#34;: &#34;1.23&#34;,&#xA;  &#34;org.opencontainers.image.source&#34;: &#34;https://github.com/redhat-appstudio-qe/konflux-test-integration&#34;,&#xA;  &#34;quay.expires-after&#34;: &#34;6h&#34;&#xA;}&#xA;[2026-04-22T13:52:55,127993458+00:00] Register sub-man&#xA;Adding the entitlement to the build&#xA;[2026-04-22T13:52:55,131213838+00:00] Add secrets&#xA;[2026-04-22T13:52:55,138672179+00:00] Run buildah build&#xA;[2026-04-22T13:52:55,139728522+00:00] buildah build --volume /tmp/entitlement:/etc/pki/entitlement --security-opt=unmask=/proc/interrupts --label architecture=x86_64 --label vcs-type=git --label vcs-ref=ed3328a539acc00b4d626fb0525fc3656cfad118 --label org.opencontainers.image.revision=ed3328a539acc00b4d626fb0525fc3656cfad118 --label org.opencontainers.image.source=https://github.com/redhat-appstudio-qe/konflux-test-integration --label quay.expires-after=6h --label build-date=2026-04-22T13:52:19Z --label org.opencontainers.image.created=2026-04-22T13:52:19Z --annotation org.opencontainers.image.revision=ed3328a539acc00b4d626fb0525fc3656cfad118 --annotation org.opencontainers.image.source=https://github.com/redhat-appstudio-qe/konflux-test-integration --annotation org.opencontainers.image.created=2026-04-22T13:52:19Z --tls-verify=true --no-cache --ulimit nofile=4096:4096 --http-proxy=false -f /tmp/Dockerfile.x5Rb0E -t quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118 . &#xA;[1/2] STEP 1/5: FROM registry.access.redhat.com/ubi8/openjdk-17:1.23 AS builder&#xA;Trying to pull registry.access.redhat.com/ubi8/openjdk-17:1.23...&#xA;Getting image source signatures&#xA;Checking if image destination supports signatures&#xA;Copying blob sha256:1e9245db1d6684fa6e841e9b335e9658f7225af2941fcdefbe4eec8e7af2c220&#xA;Copying blob sha256:d048357fb75839f8d54c470c087c578ad01acd0b0438c09ce513782902b26870&#xA;Copying config sha256:7d3108019ca265b4cb4e6e586bf055595bf32625ceb20cd1e4653b7889f07ee5&#xA;Writing manifest to image destination&#xA;Storing signatures&#xA;[1/2] STEP 2/5: WORKDIR /work&#xA;[1/2] STEP 3/5: COPY . .&#xA;[1/2] STEP 4/5: USER 0&#xA;[1/2] STEP 5/5: RUN mvn clean package -DskipTests -DskipDocsGen&#xA;[INFO] Scanning for projects...&#xA;[INFO] &#xA;[INFO] ------------------&lt; org.example:simple-java-project &gt;-------------------&#xA;[INFO] Building simple-java-project 1.0-SNAPSHOT&#xA;[INFO] --------------------------------[ jar ]---------------------------------&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-shade-plugin/3.2.4/maven-shade-plugin-3.2.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 11 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-shade-plugin/3.2.4/maven-shade-plugin-3.2.4.pom (11 kB at 39 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/34/maven-plugins-34.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 11 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/34/maven-plugins-34.pom (11 kB at 121 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/34/maven-parent-34.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 43 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/34/maven-parent-34.pom (43 kB at 535 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/23/apache-23.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 18 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/23/apache-23.pom (18 kB at 246 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-shade-plugin/3.2.4/maven-shade-plugin-3.2.4.jar&#xA;Progress (1): 2.3/134 kB&#xD;Progress (1): 5.0/134 kB&#xD;Progress (1): 7.7/134 kB&#xD;Progress (1): 10/134 kB &#xD;Progress (1): 13/134 kB&#xD;Progress (1): 16/134 kB&#xD;Progress (1): 19/134 kB&#xD;Progress (1): 21/134 kB&#xD;Progress (1): 24/134 kB&#xD;Progress (1): 28/134 kB&#xD;Progress (1): 32/134 kB&#xD;Progress (1): 36/134 kB&#xD;Progress (1): 40/134 kB&#xD;Progress (1): 45/134 kB&#xD;Progress (1): 49/134 kB&#xD;Progress (1): 53/134 kB&#xD;Progress (1): 57/134 kB&#xD;Progress (1): 61/134 kB&#xD;Progress (1): 65/134 kB&#xD;Progress (1): 69/134 kB&#xD;Progress (1): 73/134 kB&#xD;Progress (1): 77/134 kB&#xD;Progress (1): 81/134 kB&#xD;Progress (1): 86/134 kB&#xD;Progress (1): 90/134 kB&#xD;Progress (1): 92/134 kB&#xD;Progress (1): 96/134 kB&#xD;Progress (1): 100/134 kB&#xD;Progress (1): 104/134 kB&#xD;Progress (1): 108/134 kB&#xD;Progress (1): 112/134 kB&#xD;Progress (1): 116/134 kB&#xD;Progress (1): 120/134 kB&#xD;Progress (1): 125/134 kB&#xD;Progress (1): 127/134 kB&#xD;Progress (1): 131/134 kB&#xD;Progress (1): 134 kB    &#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-shade-plugin/3.2.4/maven-shade-plugin-3.2.4.jar (134 kB at 1.1 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-clean-plugin/2.5/maven-clean-plugin-2.5.pom&#xA;Progress (1): 3.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-clean-plugin/2.5/maven-clean-plugin-2.5.pom (3.9 kB at 61 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/22/maven-plugins-22.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 13 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/22/maven-plugins-22.pom (13 kB at 186 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/21/maven-parent-21.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 26 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/21/maven-parent-21.pom (26 kB at 418 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/10/apache-10.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 15 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/10/apache-10.pom (15 kB at 224 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-clean-plugin/2.5/maven-clean-plugin-2.5.jar&#xA;Progress (1): 4.1/25 kB&#xD;Progress (1): 7.7/25 kB&#xD;Progress (1): 12/25 kB &#xD;Progress (1): 16/25 kB&#xD;Progress (1): 20/25 kB&#xD;Progress (1): 24/25 kB&#xD;Progress (1): 25 kB   &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-clean-plugin/2.5/maven-clean-plugin-2.5.jar (25 kB at 368 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-resources-plugin/2.6/maven-resources-plugin-2.6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-resources-plugin/2.6/maven-resources-plugin-2.6.pom (8.1 kB at 119 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/23/maven-plugins-23.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 9.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/23/maven-plugins-23.pom (9.2 kB at 119 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/22/maven-parent-22.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 30 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/22/maven-parent-22.pom (30 kB at 413 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/11/apache-11.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 15 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/11/apache-11.pom (15 kB at 200 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-resources-plugin/2.6/maven-resources-plugin-2.6.jar&#xA;Progress (1): 4.1/30 kB&#xD;Progress (1): 7.7/30 kB&#xD;Progress (1): 12/30 kB &#xD;Progress (1): 16/30 kB&#xD;Progress (1): 20/30 kB&#xD;Progress (1): 24/30 kB&#xD;Progress (1): 28/30 kB&#xD;Progress (1): 30 kB   &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-resources-plugin/2.6/maven-resources-plugin-2.6.jar (30 kB at 332 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-compiler-plugin/3.1/maven-compiler-plugin-3.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 10 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-compiler-plugin/3.1/maven-compiler-plugin-3.1.pom (10 kB at 115 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/24/maven-plugins-24.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 11 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/24/maven-plugins-24.pom (11 kB at 161 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/23/maven-parent-23.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/23/maven-parent-23.pom (33 kB at 552 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/13/apache-13.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 14 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/13/apache-13.pom (14 kB at 212 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-compiler-plugin/3.1/maven-compiler-plugin-3.1.jar&#xA;Progress (1): 4.1/43 kB&#xD;Progress (1): 7.7/43 kB&#xD;Progress (1): 12/43 kB &#xD;Progress (1): 16/43 kB&#xD;Progress (1): 20/43 kB&#xD;Progress (1): 24/43 kB&#xD;Progress (1): 28/43 kB&#xD;Progress (1): 32/43 kB&#xD;Progress (1): 36/43 kB&#xD;Progress (1): 40/43 kB&#xD;Progress (1): 43 kB   &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-compiler-plugin/3.1/maven-compiler-plugin-3.1.jar (43 kB at 565 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-surefire-plugin/2.12.4/maven-surefire-plugin-2.12.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 10 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-surefire-plugin/2.12.4/maven-surefire-plugin-2.12.4.pom (10 kB at 152 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire/2.12.4/surefire-2.12.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 14 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire/2.12.4/surefire-2.12.4.pom (14 kB at 209 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-surefire-plugin/2.12.4/maven-surefire-plugin-2.12.4.jar&#xA;Progress (1): 4.1/30 kB&#xD;Progress (1): 7.7/30 kB&#xD;Progress (1): 12/30 kB &#xD;Progress (1): 16/30 kB&#xD;Progress (1): 20/30 kB&#xD;Progress (1): 24/30 kB&#xD;Progress (1): 28/30 kB&#xD;Progress (1): 30 kB   &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-surefire-plugin/2.12.4/maven-surefire-plugin-2.12.4.jar (30 kB at 575 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-jar-plugin/3.3.0/maven-jar-plugin-3.3.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-jar-plugin/3.3.0/maven-jar-plugin-3.3.0.pom (6.8 kB at 68 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/37/maven-plugins-37.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 9.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-plugins/37/maven-plugins-37.pom (9.9 kB at 230 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/37/maven-parent-37.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 45 kB&#xD;Progress (1): 46 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/37/maven-parent-37.pom (46 kB at 736 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/27/apache-27.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/27/apache-27.pom (20 kB at 323 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-jar-plugin/3.3.0/maven-jar-plugin-3.3.0.jar&#xA;Progress (1): 4.1/27 kB&#xD;Progress (1): 7.7/27 kB&#xD;Progress (1): 12/27 kB &#xD;Progress (1): 16/27 kB&#xD;Progress (1): 20/27 kB&#xD;Progress (1): 24/27 kB&#xD;Progress (1): 27 kB   &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-jar-plugin/3.3.0/maven-jar-plugin-3.3.0.jar (27 kB at 360 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/simple/simple-jdk17/0.1.2/simple-jdk17-0.1.2.pom&#xA;Progress (1): 3.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/simple/simple-jdk17/0.1.2/simple-jdk17-0.1.2.pom (3.6 kB at 46 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/shaded/shaded-jdk11/1.9/shaded-jdk11-1.9.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/shaded/shaded-jdk11/1.9/shaded-jdk11-1.9.pom (5.0 kB at 66 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/simple/simple-jdk8/1.2.4/simple-jdk8-1.2.4.pom&#xA;Progress (1): 3.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/simple/simple-jdk8/1.2.4/simple-jdk8-1.2.4.pom (3.6 kB at 60 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/gradle/hacbs-test-simple-gradle-jdk8/1.1/hacbs-test-simple-gradle-jdk8-1.1.pom&#xA;Progress (1): 1.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/gradle/hacbs-test-simple-gradle-jdk8/1.1/hacbs-test-simple-gradle-jdk8-1.1.pom (1.8 kB at 22 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/simple/simple-jdk17/0.1.2/simple-jdk17-0.1.2.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/shaded/shaded-jdk11/1.9/shaded-jdk11-1.9.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/simple/simple-jdk8/1.2.4/simple-jdk8-1.2.4.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/gradle/hacbs-test-simple-gradle-jdk8/1.1/hacbs-test-simple-gradle-jdk8-1.1.jar&#xA;Progress (1): 3.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/simple/simple-jdk17/0.1.2/simple-jdk17-0.1.2.jar (3.6 kB at 84 kB/s)&#xA;Progress (1): 2.3/3.6 kB&#xD;Progress (1): 3.6 kB    &#xD;Progress (2): 3.6 kB | 2.0 kB&#xD;                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/simple/simple-jdk8/1.2.4/simple-jdk8-1.2.4.jar (3.6 kB at 30 kB/s)&#xA;Progress (2): 2.0 kB | 2.3/7.1 kB&#xD;Progress (2): 2.0 kB | 5.0/7.1 kB&#xD;Progress (2): 2.0 kB | 7.1 kB    &#xD;                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/gradle/hacbs-test-simple-gradle-jdk8/1.1/hacbs-test-simple-gradle-jdk8-1.1.jar (2.0 kB at 13 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/io/github/stuartwdouglas/hacbs-test/shaded/shaded-jdk11/1.9/shaded-jdk11-1.9.jar (7.1 kB at 42 kB/s)&#xA;[INFO] &#xA;[INFO] --- maven-clean-plugin:2.5:clean (default-clean) @ simple-java-project ---&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.0.6/maven-plugin-api-2.0.6.pom&#xA;Progress (1): 1.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.0.6/maven-plugin-api-2.0.6.pom (1.5 kB at 14 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven/2.0.6/maven-2.0.6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 9.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven/2.0.6/maven-2.0.6.pom (9.0 kB at 88 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/5/maven-parent-5.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 15 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/5/maven-parent-5.pom (15 kB at 184 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/3/apache-3.pom&#xA;Progress (1): 3.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/3/apache-3.pom (3.4 kB at 28 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.0/plexus-utils-3.0.pom&#xA;Progress (1): 4.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.0/plexus-utils-3.0.pom (4.1 kB at 63 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/spice/spice-parent/16/spice-parent-16.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 8.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/spice/spice-parent/16/spice-parent-16.pom (8.4 kB at 77 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/5/forge-parent-5.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 8.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/5/forge-parent-5.pom (8.4 kB at 54 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.0.6/maven-plugin-api-2.0.6.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.0/plexus-utils-3.0.jar&#xA;Progress (1): 2.3/226 kB&#xD;Progress (1): 5.0/226 kB&#xD;Progress (2): 5.0/226 kB | 2.3/13 kB&#xD;Progress (2): 7.7/226 kB | 2.3/13 kB&#xD;Progress (2): 7.7/226 kB | 6.4/13 kB&#xD;Progress (2): 10/226 kB | 6.4/13 kB &#xD;Progress (2): 10/226 kB | 10/13 kB &#xD;Progress (2): 13/226 kB | 10/13 kB&#xD;Progress (2): 13/226 kB | 13 kB   &#xD;Progress (2): 16/226 kB | 13 kB&#xD;Progress (2): 19/226 kB | 13 kB&#xD;Progress (2): 21/226 kB | 13 kB&#xD;Progress (2): 24/226 kB | 13 kB&#xD;Progress (2): 27/226 kB | 13 kB&#xD;Progress (2): 30/226 kB | 13 kB&#xD;Progress (2): 32/226 kB | 13 kB&#xD;Progress (2): 35/226 kB | 13 kB&#xD;Progress (2): 38/226 kB | 13 kB&#xD;Progress (2): 41/226 kB | 13 kB&#xD;Progress (2): 43/226 kB | 13 kB&#xD;Progress (2): 46/226 kB | 13 kB&#xD;Progress (2): 49/226 kB | 13 kB&#xD;Progress (2): 52/226 kB | 13 kB&#xD;Progress (2): 56/226 kB | 13 kB&#xD;Progress (2): 60/226 kB | 13 kB&#xD;Progress (2): 64/226 kB | 13 kB&#xD;Progress (2): 68/226 kB | 13 kB&#xD;Progress (2): 72/226 kB | 13 kB&#xD;Progress (2): 76/226 kB | 13 kB&#xD;Progress (2): 80/226 kB | 13 kB&#xD;Progress (2): 84/226 kB | 13 kB&#xD;Progress (2): 88/226 kB | 13 kB&#xD;Progress (2): 93/226 kB | 13 kB&#xD;Progress (2): 97/226 kB | 13 kB&#xD;Progress (2): 101/226 kB | 13 kB&#xD;Progress (2): 105/226 kB | 13 kB&#xD;Progress (2): 109/226 kB | 13 kB&#xD;Progress (2): 113/226 kB | 13 kB&#xD;Progress (2): 117/226 kB | 13 kB&#xD;Progress (2): 119/226 kB | 13 kB&#xD;Progress (2): 123/226 kB | 13 kB&#xD;Progress (2): 127/226 kB | 13 kB&#xD;Progress (2): 131/226 kB | 13 kB&#xD;Progress (2): 135/226 kB | 13 kB&#xD;Progress (2): 139/226 kB | 13 kB&#xD;Progress (2): 143/226 kB | 13 kB&#xD;Progress (2): 147/226 kB | 13 kB&#xD;Progress (2): 151/226 kB | 13 kB&#xD;Progress (2): 155/226 kB | 13 kB&#xD;Progress (2): 159/226 kB | 13 kB&#xD;Progress (2): 163/226 kB | 13 kB&#xD;Progress (2): 167/226 kB | 13 kB&#xD;Progress (2): 172/226 kB | 13 kB&#xD;Progress (2): 176/226 kB | 13 kB&#xD;Progress (2): 180/226 kB | 13 kB&#xD;Progress (2): 184/226 kB | 13 kB&#xD;Progress (2): 188/226 kB | 13 kB&#xD;Progress (2): 192/226 kB | 13 kB&#xD;Progress (2): 196/226 kB | 13 kB&#xD;Progress (2): 198/226 kB | 13 kB&#xD;Progress (2): 202/226 kB | 13 kB&#xD;Progress (2): 206/226 kB | 13 kB&#xD;Progress (2): 210/226 kB | 13 kB&#xD;Progress (2): 215/226 kB | 13 kB&#xD;Progress (2): 219/226 kB | 13 kB&#xD;Progress (2): 223/226 kB | 13 kB&#xD;Progress (2): 226 kB | 13 kB    &#xD;                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.0.6/maven-plugin-api-2.0.6.jar (13 kB at 179 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.0/plexus-utils-3.0.jar (226 kB at 2.7 MB/s)&#xA;[INFO] &#xA;[INFO] --- maven-resources-plugin:2.6:resources (default-resources) @ simple-java-project ---&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.0.6/maven-project-2.0.6.pom&#xA;Progress (1): 2.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.0.6/maven-project-2.0.6.pom (2.6 kB at 42 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.0.6/maven-settings-2.0.6.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.0.6/maven-settings-2.0.6.pom (2.0 kB at 35 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.0.6/maven-model-2.0.6.pom&#xA;Progress (1): 3.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.0.6/maven-model-2.0.6.pom (3.0 kB at 45 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.4.1/plexus-utils-1.4.1.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.4.1/plexus-utils-1.4.1.pom (1.9 kB at 24 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/1.0.11/plexus-1.0.11.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 9.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/1.0.11/plexus-1.0.11.pom (9.0 kB at 106 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.0-alpha-9-stable-1/plexus-container-default-1.0-alpha-9-stable-1.pom&#xA;Progress (1): 3.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.0-alpha-9-stable-1/plexus-container-default-1.0-alpha-9-stable-1.pom (3.9 kB at 51 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-containers/1.0.3/plexus-containers-1.0.3.pom&#xA;Progress (1): 492 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-containers/1.0.3/plexus-containers-1.0.3.pom (492 B at 6.0 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/1.0.4/plexus-1.0.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/1.0.4/plexus-1.0.4.pom (5.7 kB at 83 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/junit/junit/3.8.1/junit-3.8.1.pom&#xA;Progress (1): 998 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/junit/junit/3.8.1/junit-3.8.1.pom (998 B at 13 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.0.4/plexus-utils-1.0.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.0.4/plexus-utils-1.0.4.pom (6.9 kB at 84 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/classworlds/classworlds/1.1-alpha-2/classworlds-1.1-alpha-2.pom&#xA;Progress (1): 3.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/classworlds/classworlds/1.1-alpha-2/classworlds-1.1-alpha-2.pom (3.1 kB at 43 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.0.6/maven-profile-2.0.6.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.0.6/maven-profile-2.0.6.pom (2.0 kB at 32 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.0.6/maven-artifact-manager-2.0.6.pom&#xA;Progress (1): 2.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.0.6/maven-artifact-manager-2.0.6.pom (2.6 kB at 28 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.0.6/maven-repository-metadata-2.0.6.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.0.6/maven-repository-metadata-2.0.6.pom (1.9 kB at 16 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.0.6/maven-artifact-2.0.6.pom&#xA;Progress (1): 1.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.0.6/maven-artifact-2.0.6.pom (1.6 kB at 19 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.0.6/maven-plugin-registry-2.0.6.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.0.6/maven-plugin-registry-2.0.6.pom (1.9 kB at 30 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.0.6/maven-core-2.0.6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.0.6/maven-core-2.0.6.pom (6.7 kB at 97 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.0.6/maven-plugin-parameter-documenter-2.0.6.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.0.6/maven-plugin-parameter-documenter-2.0.6.pom (1.9 kB at 30 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting-api/2.0.6/maven-reporting-api-2.0.6.pom&#xA;Progress (1): 1.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting-api/2.0.6/maven-reporting-api-2.0.6.pom (1.8 kB at 27 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting/2.0.6/maven-reporting-2.0.6.pom&#xA;Progress (1): 1.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting/2.0.6/maven-reporting-2.0.6.pom (1.4 kB at 24 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/doxia/doxia-sink-api/1.0-alpha-7/doxia-sink-api-1.0-alpha-7.pom&#xA;Progress (1): 424 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/doxia/doxia-sink-api/1.0-alpha-7/doxia-sink-api-1.0-alpha-7.pom (424 B at 4.5 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/doxia/doxia/1.0-alpha-7/doxia-1.0-alpha-7.pom&#xA;Progress (1): 3.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/doxia/doxia/1.0-alpha-7/doxia-1.0-alpha-7.pom (3.9 kB at 47 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.0.6/maven-error-diagnostics-2.0.6.pom&#xA;Progress (1): 1.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.0.6/maven-error-diagnostics-2.0.6.pom (1.7 kB at 25 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-cli/commons-cli/1.0/commons-cli-1.0.pom&#xA;Progress (1): 2.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/commons-cli/commons-cli/1.0/commons-cli-1.0.pom (2.1 kB at 36 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.0.6/maven-plugin-descriptor-2.0.6.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.0.6/maven-plugin-descriptor-2.0.6.pom (2.0 kB at 31 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interactivity-api/1.0-alpha-4/plexus-interactivity-api-1.0-alpha-4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 7.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interactivity-api/1.0-alpha-4/plexus-interactivity-api-1.0-alpha-4.pom (7.1 kB at 134 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.0.6/maven-monitor-2.0.6.pom&#xA;Progress (1): 1.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.0.6/maven-monitor-2.0.6.pom (1.3 kB at 15 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/classworlds/classworlds/1.1/classworlds-1.1.pom&#xA;Progress (1): 3.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/classworlds/classworlds/1.1/classworlds-1.1.pom (3.3 kB at 41 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/2.0.5/plexus-utils-2.0.5.pom&#xA;Progress (1): 3.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/2.0.5/plexus-utils-2.0.5.pom (3.3 kB at 34 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/2.0.6/plexus-2.0.6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 17 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/2.0.6/plexus-2.0.6.pom (17 kB at 250 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-filtering/1.1/maven-filtering-1.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-filtering/1.1/maven-filtering-1.1.pom (5.8 kB at 48 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/17/maven-shared-components-17.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 8.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/17/maven-shared-components-17.pom (8.7 kB at 109 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.15/plexus-utils-1.5.15.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.15/plexus-utils-1.5.15.pom (6.8 kB at 86 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/2.0.2/plexus-2.0.2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/2.0.2/plexus-2.0.2.pom (12 kB at 181 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.12/plexus-interpolation-1.12.pom&#xA;Progress (1): 889 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.12/plexus-interpolation-1.12.pom (889 B at 4.7 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-components/1.1.14/plexus-components-1.1.14.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-components/1.1.14/plexus-components-1.1.14.pom (5.8 kB at 110 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-build-api/0.0.4/plexus-build-api-0.0.4.pom&#xA;Progress (1): 2.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-build-api/0.0.4/plexus-build-api-0.0.4.pom (2.9 kB at 58 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/spice/spice-parent/10/spice-parent-10.pom&#xA;Progress (1): 3.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/spice/spice-parent/10/spice-parent-10.pom (3.0 kB at 49 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/3/forge-parent-3.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/3/forge-parent-3.pom (5.0 kB at 107 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.8/plexus-utils-1.5.8.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.8/plexus-utils-1.5.8.pom (8.1 kB at 183 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.13/plexus-interpolation-1.13.pom&#xA;Progress (1): 890 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.13/plexus-interpolation-1.13.pom (890 B at 11 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-components/1.1.15/plexus-components-1.1.15.pom&#xA;Progress (1): 2.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-components/1.1.15/plexus-components-1.1.15.pom (2.8 kB at 37 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/2.0.3/plexus-2.0.3.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 15 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/2.0.3/plexus-2.0.3.pom (15 kB at 242 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.0.6/maven-project-2.0.6.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.0.6/maven-profile-2.0.6.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.0.6/maven-artifact-manager-2.0.6.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.0.6/maven-plugin-registry-2.0.6.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.0.6/maven-core-2.0.6.jar&#xA;Progress (1): 4.1/116 kB&#xD;Progress (1): 7.7/116 kB&#xD;Progress (1): 12/116 kB &#xD;Progress (1): 16/116 kB&#xD;Progress (1): 20/116 kB&#xD;Progress (1): 24/116 kB&#xD;Progress (1): 28/116 kB&#xD;Progress (1): 32/116 kB&#xD;Progress (1): 36/116 kB&#xD;Progress (1): 40/116 kB&#xD;Progress (1): 45/116 kB&#xD;Progress (1): 49/116 kB&#xD;Progress (1): 53/116 kB&#xD;Progress (1): 57/116 kB&#xD;Progress (1): 61/116 kB&#xD;Progress (1): 65/116 kB&#xD;Progress (1): 69/116 kB&#xD;Progress (1): 73/116 kB&#xD;Progress (1): 77/116 kB&#xD;Progress (1): 81/116 kB&#xD;Progress (1): 86/116 kB&#xD;Progress (1): 90/116 kB&#xD;Progress (1): 94/116 kB&#xD;Progress (1): 98/116 kB&#xD;Progress (1): 102/116 kB&#xD;Progress (1): 106/116 kB&#xD;Progress (1): 110/116 kB&#xD;Progress (1): 114/116 kB&#xD;Progress (1): 116 kB    &#xD;Progress (2): 116 kB | 4.1/29 kB&#xD;Progress (2): 116 kB | 7.7/29 kB&#xD;Progress (2): 116 kB | 12/29 kB &#xD;Progress (2): 116 kB | 16/29 kB&#xD;Progress (2): 116 kB | 20/29 kB&#xD;Progress (2): 116 kB | 24/29 kB&#xD;Progress (2): 116 kB | 28/29 kB&#xD;Progress (2): 116 kB | 29 kB   &#xD;Progress (3): 116 kB | 29 kB | 2.3/57 kB&#xD;Progress (3): 116 kB | 29 kB | 5.0/57 kB&#xD;Progress (3): 116 kB | 29 kB | 7.7/57 kB&#xD;Progress (3): 116 kB | 29 kB | 10/57 kB &#xD;Progress (3): 116 kB | 29 kB | 13/57 kB&#xD;Progress (3): 116 kB | 29 kB | 16/57 kB&#xD;Progress (3): 116 kB | 29 kB | 18/57 kB&#xD;Progress (3): 116 kB | 29 kB | 21/57 kB&#xD;Progress (4): 116 kB | 29 kB | 21/57 kB | 2.3/152 kB&#xD;Progress (4): 116 kB | 29 kB | 24/57 kB | 2.3/152 kB&#xD;Progress (4): 116 kB | 29 kB | 24/57 kB | 5.0/152 kB&#xD;Progress (4): 116 kB | 29 kB | 27/57 kB | 5.0/152 kB&#xD;Progress (4): 116 kB | 29 kB | 27/57 kB | 7.7/152 kB&#xD;Progress (4): 116 kB | 29 kB | 29/57 kB | 7.7/152 kB&#xD;Progress (4): 116 kB | 29 kB | 29/57 kB | 10/152 kB &#xD;Progress (4): 116 kB | 29 kB | 32/57 kB | 10/152 kB&#xD;Progress (4): 116 kB | 29 kB | 32/57 kB | 13/152 kB&#xD;Progress (4): 116 kB | 29 kB | 35/57 kB | 13/152 kB&#xD;Progress (4): 116 kB | 29 kB | 35/57 kB | 16/152 kB&#xD;Progress (4): 116 kB | 29 kB | 38/57 kB | 16/152 kB&#xD;Progress (4): 116 kB | 29 kB | 38/57 kB | 19/152 kB&#xD;Progress (4): 116 kB | 29 kB | 40/57 kB | 19/152 kB&#xD;Progress (4): 116 kB | 29 kB | 43/57 kB | 19/152 kB&#xD;Progress (4): 116 kB | 29 kB | 43/57 kB | 21/152 kB&#xD;Progress (4): 116 kB | 29 kB | 46/57 kB | 21/152 kB&#xD;Progress (5): 116 kB | 29 kB | 46/57 kB | 21/152 kB | 3.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 46/57 kB | 24/152 kB | 3.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 48/57 kB | 24/152 kB | 3.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 48/57 kB | 27/152 kB | 3.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 51/57 kB | 27/152 kB | 3.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 51/57 kB | 27/152 kB | 7.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 54/57 kB | 27/152 kB | 7.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 54/57 kB | 30/152 kB | 7.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 30/152 kB | 7.8/35 kB   &#xD;Progress (5): 116 kB | 29 kB | 57 kB | 32/152 kB | 7.8/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 32/152 kB | 12/35 kB &#xD;Progress (5): 116 kB | 29 kB | 57 kB | 35/152 kB | 12/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 35/152 kB | 16/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 38/152 kB | 16/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 38/152 kB | 20/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 41/152 kB | 20/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 41/152 kB | 24/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 43/152 kB | 24/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 43/152 kB | 28/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 43/152 kB | 32/35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 43/152 kB | 35 kB   &#xD;Progress (5): 116 kB | 29 kB | 57 kB | 46/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 49/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 53/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 57/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 61/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 65/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 69/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 73/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 76/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 80/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 84/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 88/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 92/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 96/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 100/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 104/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 108/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 112/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 117/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 121/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 125/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 129/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 133/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 137/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 141/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 143/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 147/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 151/152 kB | 35 kB&#xD;Progress (5): 116 kB | 29 kB | 57 kB | 152 kB | 35 kB    &#xD;                                                     &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.0.6/maven-artifact-manager-2.0.6.jar (57 kB at 807 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.0.6/maven-plugin-parameter-documenter-2.0.6.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.0.6/maven-plugin-registry-2.0.6.jar (29 kB at 407 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting-api/2.0.6/maven-reporting-api-2.0.6.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.0.6/maven-project-2.0.6.jar (116 kB at 1.5 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/doxia/doxia-sink-api/1.0-alpha-7/doxia-sink-api-1.0-alpha-7.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.0.6/maven-core-2.0.6.jar (152 kB at 1.6 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.0.6/maven-repository-metadata-2.0.6.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.0.6/maven-profile-2.0.6.jar (35 kB at 363 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.0.6/maven-error-diagnostics-2.0.6.jar&#xA;Progress (1): 4.1/21 kB&#xD;Progress (1): 8.2/21 kB&#xD;Progress (1): 12/21 kB &#xD;Progress (1): 16/21 kB&#xD;Progress (1): 20/21 kB&#xD;Progress (1): 21 kB   &#xD;Progress (2): 21 kB | 4.1/5.9 kB&#xD;Progress (2): 21 kB | 5.9 kB    &#xD;Progress (3): 21 kB | 5.9 kB | 4.1/9.9 kB&#xD;Progress (3): 21 kB | 5.9 kB | 7.7/9.9 kB&#xD;Progress (3): 21 kB | 5.9 kB | 9.9 kB    &#xD;                                     &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.0.6/maven-plugin-parameter-documenter-2.0.6.jar (21 kB at 160 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-cli/commons-cli/1.0/commons-cli-1.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/doxia/doxia-sink-api/1.0-alpha-7/doxia-sink-api-1.0-alpha-7.jar (5.9 kB at 45 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.0.6/maven-plugin-descriptor-2.0.6.jar&#xA;Progress (2): 9.9 kB | 3.8/24 kB&#xD;Progress (2): 9.9 kB | 7.8/24 kB&#xD;Progress (2): 9.9 kB | 12/24 kB &#xD;Progress (2): 9.9 kB | 16/24 kB&#xD;Progress (2): 9.9 kB | 20/24 kB&#xD;Progress (2): 9.9 kB | 24/24 kB&#xD;Progress (2): 9.9 kB | 24 kB   &#xD;Progress (3): 9.9 kB | 24 kB | 4.1/37 kB&#xD;Progress (3): 9.9 kB | 24 kB | 7.7/37 kB&#xD;Progress (3): 9.9 kB | 24 kB | 12/37 kB &#xD;Progress (3): 9.9 kB | 24 kB | 16/37 kB&#xD;Progress (3): 9.9 kB | 24 kB | 20/37 kB&#xD;Progress (3): 9.9 kB | 24 kB | 24/37 kB&#xD;Progress (3): 9.9 kB | 24 kB | 28/37 kB&#xD;Progress (3): 9.9 kB | 24 kB | 32/37 kB&#xD;Progress (3): 9.9 kB | 24 kB | 36/37 kB&#xD;Progress (3): 9.9 kB | 24 kB | 37 kB   &#xD;Progress (4): 9.9 kB | 24 kB | 37 kB | 3.8/30 kB&#xD;Progress (4): 9.9 kB | 24 kB | 37 kB | 7.8/30 kB&#xD;Progress (4): 9.9 kB | 24 kB | 37 kB | 12/30 kB &#xD;Progress (4): 9.9 kB | 24 kB | 37 kB | 16/30 kB&#xD;Progress (4): 9.9 kB | 24 kB | 37 kB | 20/30 kB&#xD;Progress (4): 9.9 kB | 24 kB | 37 kB | 24/30 kB&#xD;Progress (4): 9.9 kB | 24 kB | 37 kB | 28/30 kB&#xD;Progress (4): 9.9 kB | 24 kB | 37 kB | 30 kB   &#xD;Progress (5): 9.9 kB | 24 kB | 37 kB | 30 kB | 3.8/14 kB&#xD;Progress (5): 9.9 kB | 24 kB | 37 kB | 30 kB | 7.8/14 kB&#xD;Progress (5): 9.9 kB | 24 kB | 37 kB | 30 kB | 9.9/14 kB&#xD;Progress (5): 9.9 kB | 24 kB | 37 kB | 30 kB | 14 kB    &#xD;                                                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.0.6/maven-repository-metadata-2.0.6.jar (24 kB at 143 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interactivity-api/1.0-alpha-4/plexus-interactivity-api-1.0-alpha-4.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/commons-cli/commons-cli/1.0/commons-cli-1.0.jar (30 kB at 160 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/classworlds/classworlds/1.1/classworlds-1.1.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.0.6/maven-plugin-descriptor-2.0.6.jar (37 kB at 193 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.0.6/maven-artifact-2.0.6.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.0.6/maven-error-diagnostics-2.0.6.jar (14 kB at 65 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.0.6/maven-settings-2.0.6.jar&#xA;Progress (2): 9.9 kB | 4.1/87 kB&#xD;Progress (2): 9.9 kB | 7.7/87 kB&#xD;Progress (2): 9.9 kB | 12/87 kB &#xD;Progress (2): 9.9 kB | 16/87 kB&#xD;Progress (2): 9.9 kB | 20/87 kB&#xD;Progress (2): 9.9 kB | 24/87 kB&#xD;Progress (2): 9.9 kB | 28/87 kB&#xD;Progress (2): 9.9 kB | 32/87 kB&#xD;Progress (2): 9.9 kB | 36/87 kB&#xD;Progress (2): 9.9 kB | 40/87 kB&#xD;Progress (2): 9.9 kB | 45/87 kB&#xD;Progress (2): 9.9 kB | 49/87 kB&#xD;Progress (2): 9.9 kB | 53/87 kB&#xD;Progress (2): 9.9 kB | 57/87 kB&#xD;Progress (2): 9.9 kB | 61/87 kB&#xD;Progress (2): 9.9 kB | 65/87 kB&#xD;Progress (2): 9.9 kB | 69/87 kB&#xD;Progress (2): 9.9 kB | 73/87 kB&#xD;Progress (2): 9.9 kB | 77/87 kB&#xD;Progress (2): 9.9 kB | 81/87 kB&#xD;Progress (2): 9.9 kB | 86/87 kB&#xD;Progress (2): 9.9 kB | 87 kB   &#xD;Progress (3): 9.9 kB | 87 kB | 3.8/13 kB&#xD;Progress (3): 9.9 kB | 87 kB | 7.8/13 kB&#xD;Progress (3): 9.9 kB | 87 kB | 12/13 kB &#xD;Progress (3): 9.9 kB | 87 kB | 13 kB   &#xD;Progress (4): 9.9 kB | 87 kB | 13 kB | 3.8/38 kB&#xD;Progress (4): 9.9 kB | 87 kB | 13 kB | 7.8/38 kB&#xD;Progress (4): 9.9 kB | 87 kB | 13 kB | 12/38 kB &#xD;Progress (4): 9.9 kB | 87 kB | 13 kB | 16/38 kB&#xD;Progress (4): 9.9 kB | 87 kB | 13 kB | 20/38 kB&#xD;Progress (4): 9.9 kB | 87 kB | 13 kB | 24/38 kB&#xD;Progress (4): 9.9 kB | 87 kB | 13 kB | 28/38 kB&#xD;Progress (4): 9.9 kB | 87 kB | 13 kB | 32/38 kB&#xD;                                               &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting-api/2.0.6/maven-reporting-api-2.0.6.jar (9.9 kB at 45 kB/s)&#xA;Progress (3): 87 kB | 13 kB | 36/38 kB&#xD;                                      &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.0.6/maven-model-2.0.6.jar&#xA;Progress (3): 87 kB | 13 kB | 38 kB&#xD;                                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.0.6/maven-artifact-2.0.6.jar (87 kB at 381 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.0.6/maven-monitor-2.0.6.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interactivity-api/1.0-alpha-4/plexus-interactivity-api-1.0-alpha-4.jar (13 kB at 54 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.0-alpha-9-stable-1/plexus-container-default-1.0-alpha-9-stable-1.jar&#xA;Progress (2): 38 kB | 4.1/10 kB&#xD;Progress (2): 38 kB | 7.7/10 kB&#xD;Progress (2): 38 kB | 10 kB    &#xD;                           &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.0.6/maven-monitor-2.0.6.jar (10 kB at 38 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/junit/junit/3.8.1/junit-3.8.1.jar&#xA;Progress (2): 38 kB | 3.8/49 kB&#xD;Progress (2): 38 kB | 7.8/49 kB&#xD;Progress (2): 38 kB | 12/49 kB &#xD;Progress (2): 38 kB | 16/49 kB&#xD;Progress (2): 38 kB | 20/49 kB&#xD;Progress (2): 38 kB | 24/49 kB&#xD;Progress (2): 38 kB | 28/49 kB&#xD;Progress (2): 38 kB | 32/49 kB&#xD;Progress (2): 38 kB | 37/49 kB&#xD;Progress (2): 38 kB | 41/49 kB&#xD;Progress (2): 38 kB | 45/49 kB&#xD;Progress (2): 38 kB | 49/49 kB&#xD;Progress (2): 38 kB | 49 kB   &#xD;Progress (3): 38 kB | 49 kB | 4.1/121 kB&#xD;Progress (3): 38 kB | 49 kB | 7.7/121 kB&#xD;Progress (3): 38 kB | 49 kB | 12/121 kB &#xD;Progress (3): 38 kB | 49 kB | 16/121 kB&#xD;Progress (3): 38 kB | 49 kB | 20/121 kB&#xD;Progress (3): 38 kB | 49 kB | 24/121 kB&#xD;Progress (3): 38 kB | 49 kB | 28/121 kB&#xD;Progress (3): 38 kB | 49 kB | 32/121 kB&#xD;Progress (3): 38 kB | 49 kB | 36/121 kB&#xD;Progress (3): 38 kB | 49 kB | 40/121 kB&#xD;Progress (3): 38 kB | 49 kB | 45/121 kB&#xD;Progress (3): 38 kB | 49 kB | 49/121 kB&#xD;Progress (3): 38 kB | 49 kB | 53/121 kB&#xD;Progress (3): 38 kB | 49 kB | 57/121 kB&#xD;Progress (3): 38 kB | 49 kB | 61/121 kB&#xD;Progress (3): 38 kB | 49 kB | 65/121 kB&#xD;Progress (3): 38 kB | 49 kB | 69/121 kB&#xD;Progress (3): 38 kB | 49 kB | 73/121 kB&#xD;Progress (3): 38 kB | 49 kB | 77/121 kB&#xD;Progress (3): 38 kB | 49 kB | 81/121 kB&#xD;Progress (3): 38 kB | 49 kB | 86/121 kB&#xD;Progress (3): 38 kB | 49 kB | 90/121 kB&#xD;Progress (3): 38 kB | 49 kB | 94/121 kB&#xD;Progress (3): 38 kB | 49 kB | 98/121 kB&#xD;Progress (3): 38 kB | 49 kB | 102/121 kB&#xD;Progress (3): 38 kB | 49 kB | 106/121 kB&#xD;Progress (3): 38 kB | 49 kB | 110/121 kB&#xD;Progress (3): 38 kB | 49 kB | 114/121 kB&#xD;Progress (3): 38 kB | 49 kB | 118/121 kB&#xD;Progress (3): 38 kB | 49 kB | 121 kB    &#xD;Progress (4): 38 kB | 49 kB | 121 kB | 3.8/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 7.8/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 12/194 kB &#xD;Progress (4): 38 kB | 49 kB | 121 kB | 16/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 20/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 24/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 28/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 32/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 37/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 41/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 45/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 49/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 53/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 57/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 61/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 65/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 69/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 73/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 77/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 82/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 86/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 90/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 94/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 98/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 102/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 106/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 110/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 114/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 118/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 123/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 127/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 131/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 135/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 139/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 143/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 147/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 151/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 155/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 159/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 163/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 167/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 172/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 176/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 180/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 184/194 kB&#xD;Progress (4): 38 kB | 49 kB | 121 kB | 188/194 kB&#xD;                                                 &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/classworlds/classworlds/1.1/classworlds-1.1.jar (38 kB at 124 kB/s)&#xA;Progress (3): 49 kB | 121 kB | 192/194 kB&#xD;                                         &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/2.0.5/plexus-utils-2.0.5.jar&#xA;Progress (3): 49 kB | 121 kB | 194 kB&#xD;                                     &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/junit/junit/3.8.1/junit-3.8.1.jar (121 kB at 381 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-filtering/1.1/maven-filtering-1.1.jar&#xA;Progress (3): 49 kB | 194 kB | 4.1/223 kB&#xD;Progress (4): 49 kB | 194 kB | 4.1/223 kB | 4.1/43 kB&#xD;Progress (4): 49 kB | 194 kB | 7.7/223 kB | 4.1/43 kB&#xD;Progress (4): 49 kB | 194 kB | 7.7/223 kB | 7.7/43 kB&#xD;Progress (4): 49 kB | 194 kB | 12/223 kB | 7.7/43 kB &#xD;Progress (4): 49 kB | 194 kB | 16/223 kB | 7.7/43 kB&#xD;Progress (4): 49 kB | 194 kB | 16/223 kB | 12/43 kB &#xD;Progress (4): 49 kB | 194 kB | 16/223 kB | 16/43 kB&#xD;Progress (4): 49 kB | 194 kB | 16/223 kB | 20/43 kB&#xD;Progress (4): 49 kB | 194 kB | 16/223 kB | 24/43 kB&#xD;Progress (4): 49 kB | 194 kB | 20/223 kB | 24/43 kB&#xD;Progress (4): 49 kB | 194 kB | 24/223 kB | 24/43 kB&#xD;Progress (4): 49 kB | 194 kB | 28/223 kB | 24/43 kB&#xD;Progress (4): 49 kB | 194 kB | 32/223 kB | 24/43 kB&#xD;Progress (4): 49 kB | 194 kB | 32/223 kB | 28/43 kB&#xD;Progress (4): 49 kB | 194 kB | 32/223 kB | 32/43 kB&#xD;Progress (4): 49 kB | 194 kB | 32/223 kB | 36/43 kB&#xD;Progress (4): 49 kB | 194 kB | 32/223 kB | 40/43 kB&#xD;Progress (4): 49 kB | 194 kB | 36/223 kB | 40/43 kB&#xD;Progress (4): 49 kB | 194 kB | 40/223 kB | 40/43 kB&#xD;Progress (4): 49 kB | 194 kB | 40/223 kB | 43 kB   &#xD;Progress (4): 49 kB | 194 kB | 45/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 49/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 53/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 57/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 61/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 65/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 69/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 73/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 77/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 81/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 86/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 90/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 94/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 98/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 102/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 106/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 110/223 kB | 43 kB&#xD;Progress (4): 49 kB | 194 kB | 114/223 kB | 43 kB&#xD;                                                 &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.0-alpha-9-stable-1/plexus-container-default-1.0-alpha-9-stable-1.jar (194 kB at 558 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-build-api/0.0.4/plexus-build-api-0.0.4.jar&#xA;Progress (3): 49 kB | 118/223 kB | 43 kB&#xD;Progress (3): 49 kB | 122/223 kB | 43 kB&#xD;Progress (3): 49 kB | 126/223 kB | 43 kB&#xD;Progress (3): 49 kB | 131/223 kB | 43 kB&#xD;Progress (3): 49 kB | 135/223 kB | 43 kB&#xD;Progress (3): 49 kB | 139/223 kB | 43 kB&#xD;Progress (3): 49 kB | 143/223 kB | 43 kB&#xD;Progress (3): 49 kB | 147/223 kB | 43 kB&#xD;Progress (3): 49 kB | 151/223 kB | 43 kB&#xD;Progress (3): 49 kB | 155/223 kB | 43 kB&#xD;Progress (3): 49 kB | 159/223 kB | 43 kB&#xD;Progress (3): 49 kB | 163/223 kB | 43 kB&#xD;Progress (3): 49 kB | 167/223 kB | 43 kB&#xD;Progress (3): 49 kB | 172/223 kB | 43 kB&#xD;Progress (3): 49 kB | 176/223 kB | 43 kB&#xD;Progress (3): 49 kB | 180/223 kB | 43 kB&#xD;Progress (3): 49 kB | 184/223 kB | 43 kB&#xD;Progress (3): 49 kB | 188/223 kB | 43 kB&#xD;Progress (3): 49 kB | 192/223 kB | 43 kB&#xD;Progress (3): 49 kB | 196/223 kB | 43 kB&#xD;Progress (3): 49 kB | 200/223 kB | 43 kB&#xD;Progress (3): 49 kB | 204/223 kB | 43 kB&#xD;Progress (3): 49 kB | 208/223 kB | 43 kB&#xD;Progress (3): 49 kB | 212/223 kB | 43 kB&#xD;Progress (3): 49 kB | 217/223 kB | 43 kB&#xD;Progress (3): 49 kB | 221/223 kB | 43 kB&#xD;Progress (3): 49 kB | 223 kB | 43 kB    &#xD;                                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.0.6/maven-settings-2.0.6.jar (49 kB at 134 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.13/plexus-interpolation-1.13.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-filtering/1.1/maven-filtering-1.1.jar (43 kB at 115 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/2.0.5/plexus-utils-2.0.5.jar (223 kB at 592 kB/s)&#xA;Progress (1): 4.1/6.8 kB&#xD;Progress (1): 6.8 kB    &#xD;Progress (2): 6.8 kB | 3.8/86 kB&#xD;Progress (2): 6.8 kB | 7.8/86 kB&#xD;Progress (2): 6.8 kB | 12/86 kB &#xD;Progress (2): 6.8 kB | 16/86 kB&#xD;Progress (2): 6.8 kB | 20/86 kB&#xD;Progress (2): 6.8 kB | 24/86 kB&#xD;Progress (2): 6.8 kB | 28/86 kB&#xD;Progress (2): 6.8 kB | 32/86 kB&#xD;Progress (2): 6.8 kB | 37/86 kB&#xD;Progress (2): 6.8 kB | 41/86 kB&#xD;Progress (2): 6.8 kB | 45/86 kB&#xD;Progress (2): 6.8 kB | 49/86 kB&#xD;Progress (2): 6.8 kB | 53/86 kB&#xD;Progress (2): 6.8 kB | 57/86 kB&#xD;Progress (2): 6.8 kB | 61/86 kB&#xD;Progress (2): 6.8 kB | 65/86 kB&#xD;Progress (2): 6.8 kB | 69/86 kB&#xD;Progress (2): 6.8 kB | 73/86 kB&#xD;Progress (2): 6.8 kB | 77/86 kB&#xD;Progress (2): 6.8 kB | 82/86 kB&#xD;Progress (2): 6.8 kB | 86/86 kB&#xD;Progress (2): 6.8 kB | 86 kB   &#xD;Progress (3): 6.8 kB | 86 kB | 3.8/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 7.8/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 12/61 kB &#xD;Progress (3): 6.8 kB | 86 kB | 16/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 20/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 24/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 28/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 32/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 37/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 41/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 45/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 49/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 53/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 57/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 61/61 kB&#xD;Progress (3): 6.8 kB | 86 kB | 61 kB   &#xD;                                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.0.6/maven-model-2.0.6.jar (86 kB at 196 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-build-api/0.0.4/plexus-build-api-0.0.4.jar (6.8 kB at 15 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.13/plexus-interpolation-1.13.jar (61 kB at 135 kB/s)&#xA;[WARNING] Using platform encoding (UTF-8 actually) to copy filtered resources, i.e. build is platform dependent!&#xA;[INFO] skip non existing resourceDirectory /work/src/main/resources&#xA;[INFO] &#xA;[INFO] --- maven-compiler-plugin:3.1:compile (default-compile) @ simple-java-project ---&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.0.9/maven-plugin-api-2.0.9.pom&#xA;Progress (1): 1.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.0.9/maven-plugin-api-2.0.9.pom (1.5 kB at 17 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven/2.0.9/maven-2.0.9.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 19 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven/2.0.9/maven-2.0.9.pom (19 kB at 163 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/8/maven-parent-8.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 24 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/8/maven-parent-8.pom (24 kB at 274 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/4/apache-4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/4/apache-4.pom (4.5 kB at 47 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.0.9/maven-artifact-2.0.9.pom&#xA;Progress (1): 1.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.0.9/maven-artifact-2.0.9.pom (1.6 kB at 23 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.1/plexus-utils-1.5.1.pom&#xA;Progress (1): 2.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.1/plexus-utils-1.5.1.pom (2.3 kB at 29 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.0.9/maven-core-2.0.9.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 7.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.0.9/maven-core-2.0.9.pom (7.8 kB at 101 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.0.9/maven-settings-2.0.9.pom&#xA;Progress (1): 2.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.0.9/maven-settings-2.0.9.pom (2.1 kB at 28 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.0.9/maven-model-2.0.9.pom&#xA;Progress (1): 3.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.0.9/maven-model-2.0.9.pom (3.1 kB at 53 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.0.9/maven-plugin-parameter-documenter-2.0.9.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.0.9/maven-plugin-parameter-documenter-2.0.9.pom (2.0 kB at 17 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.0.9/maven-profile-2.0.9.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.0.9/maven-profile-2.0.9.pom (2.0 kB at 24 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.0.9/maven-repository-metadata-2.0.9.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.0.9/maven-repository-metadata-2.0.9.pom (1.9 kB at 12 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.0.9/maven-error-diagnostics-2.0.9.pom&#xA;Progress (1): 1.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.0.9/maven-error-diagnostics-2.0.9.pom (1.7 kB at 21 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.0.9/maven-project-2.0.9.pom&#xA;Progress (1): 2.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.0.9/maven-project-2.0.9.pom (2.7 kB at 16 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.0.9/maven-artifact-manager-2.0.9.pom&#xA;Progress (1): 2.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.0.9/maven-artifact-manager-2.0.9.pom (2.7 kB at 22 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.0.9/maven-plugin-registry-2.0.9.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.0.9/maven-plugin-registry-2.0.9.pom (2.0 kB at 16 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.0.9/maven-plugin-descriptor-2.0.9.pom&#xA;Progress (1): 2.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.0.9/maven-plugin-descriptor-2.0.9.pom (2.1 kB at 26 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.0.9/maven-monitor-2.0.9.pom&#xA;Progress (1): 1.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.0.9/maven-monitor-2.0.9.pom (1.3 kB at 18 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-toolchain/1.0/maven-toolchain-1.0.pom&#xA;Progress (1): 3.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-toolchain/1.0/maven-toolchain-1.0.pom (3.4 kB at 40 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-utils/0.1/maven-shared-utils-0.1.pom&#xA;Progress (1): 4.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-utils/0.1/maven-shared-utils-0.1.pom (4.0 kB at 33 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/18/maven-shared-components-18.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/18/maven-shared-components-18.pom (4.9 kB at 33 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/code/findbugs/jsr305/2.0.1/jsr305-2.0.1.pom&#xA;Progress (1): 965 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/code/findbugs/jsr305/2.0.1/jsr305-2.0.1.pom (965 B at 7.0 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-incremental/1.1/maven-shared-incremental-1.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-incremental/1.1/maven-shared-incremental-1.1.pom (4.7 kB at 46 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/19/maven-shared-components-19.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/19/maven-shared-components-19.pom (6.4 kB at 90 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.2.1/maven-plugin-api-2.2.1.pom&#xA;Progress (1): 1.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.2.1/maven-plugin-api-2.2.1.pom (1.5 kB at 23 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven/2.2.1/maven-2.2.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 22 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven/2.2.1/maven-2.2.1.pom (22 kB at 386 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/11/maven-parent-11.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 32 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/11/maven-parent-11.pom (32 kB at 559 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/5/apache-5.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/5/apache-5.pom (4.1 kB at 60 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.2.1/maven-core-2.2.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.2.1/maven-core-2.2.1.pom (12 kB at 134 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.2.1/maven-settings-2.2.1.pom&#xA;Progress (1): 2.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.2.1/maven-settings-2.2.1.pom (2.2 kB at 40 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.2.1/maven-model-2.2.1.pom&#xA;Progress (1): 3.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.2.1/maven-model-2.2.1.pom (3.2 kB at 55 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.11/plexus-interpolation-1.11.pom&#xA;Progress (1): 889 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.11/plexus-interpolation-1.11.pom (889 B at 19 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.2.1/maven-plugin-parameter-documenter-2.2.1.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.2.1/maven-plugin-parameter-documenter-2.2.1.pom (2.0 kB at 34 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-jdk14/1.5.6/slf4j-jdk14-1.5.6.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-jdk14/1.5.6/slf4j-jdk14-1.5.6.pom (1.9 kB at 33 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-parent/1.5.6/slf4j-parent-1.5.6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 7.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-parent/1.5.6/slf4j-parent-1.5.6.pom (7.9 kB at 158 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.5.6/slf4j-api-1.5.6.pom&#xA;Progress (1): 3.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.5.6/slf4j-api-1.5.6.pom (3.0 kB at 51 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/jcl-over-slf4j/1.5.6/jcl-over-slf4j-1.5.6.pom&#xA;Progress (1): 2.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/jcl-over-slf4j/1.5.6/jcl-over-slf4j-1.5.6.pom (2.2 kB at 30 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.2.1/maven-profile-2.2.1.pom&#xA;Progress (1): 2.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.2.1/maven-profile-2.2.1.pom (2.2 kB at 20 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.2.1/maven-artifact-2.2.1.pom&#xA;Progress (1): 1.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.2.1/maven-artifact-2.2.1.pom (1.6 kB at 14 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.2.1/maven-repository-metadata-2.2.1.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.2.1/maven-repository-metadata-2.2.1.pom (1.9 kB at 22 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.2.1/maven-error-diagnostics-2.2.1.pom&#xA;Progress (1): 1.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.2.1/maven-error-diagnostics-2.2.1.pom (1.7 kB at 27 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.2.1/maven-project-2.2.1.pom&#xA;Progress (1): 2.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.2.1/maven-project-2.2.1.pom (2.8 kB at 51 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.2.1/maven-artifact-manager-2.2.1.pom&#xA;Progress (1): 3.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.2.1/maven-artifact-manager-2.2.1.pom (3.1 kB at 34 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/backport-util-concurrent/backport-util-concurrent/3.1/backport-util-concurrent-3.1.pom&#xA;Progress (1): 880 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/backport-util-concurrent/backport-util-concurrent/3.1/backport-util-concurrent-3.1.pom (880 B at 15 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.2.1/maven-plugin-registry-2.2.1.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.2.1/maven-plugin-registry-2.2.1.pom (1.9 kB at 31 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.2.1/maven-plugin-descriptor-2.2.1.pom&#xA;Progress (1): 2.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.2.1/maven-plugin-descriptor-2.2.1.pom (2.1 kB at 36 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.2.1/maven-monitor-2.2.1.pom&#xA;Progress (1): 1.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.2.1/maven-monitor-2.2.1.pom (1.3 kB at 15 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-sec-dispatcher/1.3/plexus-sec-dispatcher-1.3.pom&#xA;Progress (1): 3.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-sec-dispatcher/1.3/plexus-sec-dispatcher-1.3.pom (3.0 kB at 43 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/spice/spice-parent/12/spice-parent-12.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/spice/spice-parent/12/spice-parent-12.pom (6.8 kB at 61 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/4/forge-parent-4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 8.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/4/forge-parent-4.pom (8.4 kB at 82 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.5/plexus-utils-1.5.5.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.5/plexus-utils-1.5.5.pom (5.1 kB at 51 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-cipher/1.4/plexus-cipher-1.4.pom&#xA;Progress (1): 2.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-cipher/1.4/plexus-cipher-1.4.pom (2.1 kB at 22 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-component-annotations/1.5.5/plexus-component-annotations-1.5.5.pom&#xA;Progress (1): 815 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-component-annotations/1.5.5/plexus-component-annotations-1.5.5.pom (815 B at 14 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-containers/1.5.5/plexus-containers-1.5.5.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-containers/1.5.5/plexus-containers-1.5.5.pom (4.2 kB at 42 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/2.0.7/plexus-2.0.7.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 17 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/2.0.7/plexus-2.0.7.pom (17 kB at 141 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-api/2.2/plexus-compiler-api-2.2.pom&#xA;Progress (1): 865 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-api/2.2/plexus-compiler-api-2.2.pom (865 B at 7.6 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler/2.2/plexus-compiler-2.2.pom&#xA;Progress (1): 3.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler/2.2/plexus-compiler-2.2.pom (3.6 kB at 33 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-components/1.3.1/plexus-components-1.3.1.pom&#xA;Progress (1): 3.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-components/1.3.1/plexus-components-1.3.1.pom (3.1 kB at 41 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/3.3.1/plexus-3.3.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/3.3.1/plexus-3.3.1.pom (20 kB at 288 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/spice/spice-parent/17/spice-parent-17.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/spice/spice-parent/17/spice-parent-17.pom (6.8 kB at 80 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/10/forge-parent-10.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 14 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/10/forge-parent-10.pom (14 kB at 108 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.0.8/plexus-utils-3.0.8.pom&#xA;Progress (1): 3.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.0.8/plexus-utils-3.0.8.pom (3.1 kB at 32 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/3.2/plexus-3.2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 19 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/3.2/plexus-3.2.pom (19 kB at 298 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-manager/2.2/plexus-compiler-manager-2.2.pom&#xA;Progress (1): 690 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-manager/2.2/plexus-compiler-manager-2.2.pom (690 B at 8.2 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-javac/2.2/plexus-compiler-javac-2.2.pom&#xA;Progress (1): 769 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-javac/2.2/plexus-compiler-javac-2.2.pom (769 B at 7.8 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compilers/2.2/plexus-compilers-2.2.pom&#xA;Progress (1): 1.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compilers/2.2/plexus-compilers-2.2.pom (1.2 kB at 11 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.5.5/plexus-container-default-1.5.5.pom&#xA;Progress (1): 2.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.5.5/plexus-container-default-1.5.5.pom (2.8 kB at 21 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.4.5/plexus-utils-1.4.5.pom&#xA;Progress (1): 2.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.4.5/plexus-utils-1.4.5.pom (2.3 kB at 18 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-classworlds/2.2.2/plexus-classworlds-2.2.2.pom&#xA;Progress (1): 4.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-classworlds/2.2.2/plexus-classworlds-2.2.2.pom (4.0 kB at 36 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/xbean/xbean-reflect/3.4/xbean-reflect-3.4.pom&#xA;Progress (1): 2.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/xbean/xbean-reflect/3.4/xbean-reflect-3.4.pom (2.8 kB at 28 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/xbean/xbean/3.4/xbean-3.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 19 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/xbean/xbean/3.4/xbean-3.4.pom (19 kB at 277 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/log4j/log4j/1.2.12/log4j-1.2.12.pom&#xA;Progress (1): 145 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/log4j/log4j/1.2.12/log4j-1.2.12.pom (145 B at 2.3 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-logging/commons-logging-api/1.1/commons-logging-api-1.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/commons-logging/commons-logging-api/1.1/commons-logging-api-1.1.pom (5.3 kB at 53 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/collections/google-collections/1.0/google-collections-1.0.pom&#xA;Progress (1): 2.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/collections/google-collections/1.0/google-collections-1.0.pom (2.5 kB at 24 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/google/1/google-1.pom&#xA;Progress (1): 1.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/google/1/google-1.pom (1.6 kB at 23 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/junit/junit/3.8.2/junit-3.8.2.pom&#xA;Progress (1): 747 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/junit/junit/3.8.2/junit-3.8.2.pom (747 B at 10 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.0.9/maven-plugin-api-2.0.9.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.0.9/maven-artifact-2.0.9.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.1/plexus-utils-1.5.1.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.0.9/maven-core-2.0.9.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.0.9/maven-settings-2.0.9.jar&#xA;Progress (1): 4.1/13 kB&#xD;Progress (1): 7.7/13 kB&#xD;Progress (1): 12/13 kB &#xD;Progress (1): 13 kB   &#xD;Progress (2): 13 kB | 4.1/160 kB&#xD;Progress (2): 13 kB | 8.2/160 kB&#xD;Progress (2): 13 kB | 12/160 kB &#xD;Progress (2): 13 kB | 16/160 kB&#xD;Progress (2): 13 kB | 20/160 kB&#xD;Progress (2): 13 kB | 25/160 kB&#xD;Progress (2): 13 kB | 29/160 kB&#xD;Progress (2): 13 kB | 33/160 kB&#xD;Progress (2): 13 kB | 37/160 kB&#xD;Progress (2): 13 kB | 41/160 kB&#xD;Progress (2): 13 kB | 45/160 kB&#xD;Progress (2): 13 kB | 49/160 kB&#xD;Progress (2): 13 kB | 53/160 kB&#xD;Progress (2): 13 kB | 57/160 kB&#xD;Progress (2): 13 kB | 61/160 kB&#xD;Progress (2): 13 kB | 66/160 kB&#xD;Progress (2): 13 kB | 70/160 kB&#xD;Progress (2): 13 kB | 74/160 kB&#xD;Progress (2): 13 kB | 78/160 kB&#xD;Progress (2): 13 kB | 82/160 kB&#xD;Progress (2): 13 kB | 86/160 kB&#xD;Progress (2): 13 kB | 90/160 kB&#xD;Progress (2): 13 kB | 94/160 kB&#xD;Progress (2): 13 kB | 98/160 kB&#xD;Progress (2): 13 kB | 102/160 kB&#xD;Progress (2): 13 kB | 106/160 kB&#xD;Progress (2): 13 kB | 111/160 kB&#xD;Progress (2): 13 kB | 115/160 kB&#xD;Progress (2): 13 kB | 119/160 kB&#xD;Progress (2): 13 kB | 123/160 kB&#xD;Progress (3): 13 kB | 123/160 kB | 4.1/49 kB&#xD;Progress (3): 13 kB | 127/160 kB | 4.1/49 kB&#xD;Progress (3): 13 kB | 127/160 kB | 7.7/49 kB&#xD;Progress (3): 13 kB | 131/160 kB | 7.7/49 kB&#xD;Progress (3): 13 kB | 135/160 kB | 7.7/49 kB&#xD;Progress (3): 13 kB | 135/160 kB | 12/49 kB &#xD;Progress (3): 13 kB | 135/160 kB | 16/49 kB&#xD;Progress (3): 13 kB | 135/160 kB | 20/49 kB&#xD;Progress (3): 13 kB | 135/160 kB | 24/49 kB&#xD;Progress (3): 13 kB | 139/160 kB | 24/49 kB&#xD;Progress (3): 13 kB | 139/160 kB | 28/49 kB&#xD;Progress (3): 13 kB | 143/160 kB | 28/49 kB&#xD;Progress (3): 13 kB | 143/160 kB | 32/49 kB&#xD;Progress (3): 13 kB | 147/160 kB | 32/49 kB&#xD;Progress (3): 13 kB | 147/160 kB | 36/49 kB&#xD;Progress (3): 13 kB | 152/160 kB | 36/49 kB&#xD;Progress (3): 13 kB | 152/160 kB | 40/49 kB&#xD;Progress (3): 13 kB | 156/160 kB | 40/49 kB&#xD;Progress (3): 13 kB | 160 kB | 40/49 kB    &#xD;Progress (3): 13 kB | 160 kB | 45/49 kB&#xD;Progress (3): 13 kB | 160 kB | 49/49 kB&#xD;Progress (3): 13 kB | 160 kB | 49 kB   &#xD;Progress (4): 13 kB | 160 kB | 49 kB | 4.1/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 8.2/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 12/89 kB &#xD;Progress (4): 13 kB | 160 kB | 49 kB | 16/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 20/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 25/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 29/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 33/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 37/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 41/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 45/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 49/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 53/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 57/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 61/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 66/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 70/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 74/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 78/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 82/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 86/89 kB&#xD;Progress (4): 13 kB | 160 kB | 49 kB | 89 kB   &#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 4.1/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 7.7/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 12/211 kB &#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 16/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 20/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 24/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 28/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 32/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 36/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 40/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 45/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 49/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 53/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 57/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 61/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 65/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 69/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 73/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 77/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 81/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 86/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 90/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 94/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 98/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 102/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 106/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 110/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 114/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 118/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 122/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 126/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 131/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 135/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 139/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 143/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 147/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 151/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 155/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 159/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 163/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 167/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 172/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 176/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 180/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 184/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 188/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 192/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 196/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 200/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 204/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 208/211 kB&#xD;Progress (5): 13 kB | 160 kB | 49 kB | 89 kB | 211 kB    &#xD;                                                     &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/2.0.9/maven-settings-2.0.9.jar (49 kB at 756 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.0.9/maven-plugin-parameter-documenter-2.0.9.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/2.0.9/maven-core-2.0.9.jar (160 kB at 2.4 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.0.9/maven-profile-2.0.9.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/2.0.9/maven-plugin-api-2.0.9.jar (13 kB at 159 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.0.9/maven-model-2.0.9.jar&#xA;Progress (3): 89 kB | 211 kB | 4.1/21 kB&#xD;Progress (3): 89 kB | 211 kB | 7.7/21 kB&#xD;Progress (3): 89 kB | 211 kB | 12/21 kB &#xD;Progress (3): 89 kB | 211 kB | 16/21 kB&#xD;Progress (3): 89 kB | 211 kB | 20/21 kB&#xD;                                       &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/2.0.9/maven-artifact-2.0.9.jar (89 kB at 1.0 MB/s)&#xA;Progress (2): 211 kB | 21 kB&#xD;                            &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.0.9/maven-repository-metadata-2.0.9.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/1.5.1/plexus-utils-1.5.1.jar (211 kB at 2.4 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.0.9/maven-error-diagnostics-2.0.9.jar&#xA;Progress (2): 21 kB | 4.1/35 kB&#xD;Progress (2): 21 kB | 7.7/35 kB&#xD;Progress (2): 21 kB | 12/35 kB &#xD;Progress (2): 21 kB | 16/35 kB&#xD;Progress (2): 21 kB | 20/35 kB&#xD;Progress (2): 21 kB | 24/35 kB&#xD;Progress (2): 21 kB | 28/35 kB&#xD;Progress (2): 21 kB | 32/35 kB&#xD;Progress (2): 21 kB | 35 kB   &#xD;                           &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-parameter-documenter/2.0.9/maven-plugin-parameter-documenter-2.0.9.jar (21 kB at 190 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.0.9/maven-project-2.0.9.jar&#xA;Progress (2): 35 kB | 4.1/87 kB&#xD;Progress (2): 35 kB | 7.7/87 kB&#xD;Progress (2): 35 kB | 12/87 kB &#xD;Progress (2): 35 kB | 16/87 kB&#xD;Progress (2): 35 kB | 20/87 kB&#xD;Progress (2): 35 kB | 24/87 kB&#xD;Progress (2): 35 kB | 28/87 kB&#xD;Progress (2): 35 kB | 32/87 kB&#xD;Progress (2): 35 kB | 36/87 kB&#xD;Progress (2): 35 kB | 40/87 kB&#xD;Progress (2): 35 kB | 45/87 kB&#xD;Progress (2): 35 kB | 49/87 kB&#xD;                              &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-profile/2.0.9/maven-profile-2.0.9.jar (35 kB at 300 kB/s)&#xA;Progress (1): 53/87 kB&#xD;                      &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.0.9/maven-plugin-registry-2.0.9.jar&#xA;Progress (1): 57/87 kB&#xD;Progress (1): 61/87 kB&#xD;Progress (1): 65/87 kB&#xD;Progress (1): 69/87 kB&#xD;Progress (1): 73/87 kB&#xD;Progress (1): 77/87 kB&#xD;Progress (1): 81/87 kB&#xD;Progress (1): 86/87 kB&#xD;Progress (1): 87 kB   &#xD;Progress (2): 87 kB | 4.1/25 kB&#xD;Progress (2): 87 kB | 7.7/25 kB&#xD;Progress (2): 87 kB | 12/25 kB &#xD;Progress (2): 87 kB | 16/25 kB&#xD;Progress (3): 87 kB | 16/25 kB | 4.1/14 kB&#xD;Progress (3): 87 kB | 16/25 kB | 7.7/14 kB&#xD;Progress (3): 87 kB | 16/25 kB | 12/14 kB &#xD;Progress (3): 87 kB | 16/25 kB | 14 kB   &#xD;Progress (3): 87 kB | 20/25 kB | 14 kB&#xD;Progress (3): 87 kB | 24/25 kB | 14 kB&#xD;Progress (3): 87 kB | 25 kB | 14 kB   &#xD;Progress (4): 87 kB | 25 kB | 14 kB | 4.1/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 7.7/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 12/122 kB &#xD;Progress (4): 87 kB | 25 kB | 14 kB | 16/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 20/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 24/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 28/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 32/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 36/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 40/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 45/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 49/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 53/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 57/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 61/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 65/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 69/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 73/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 77/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 81/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 86/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 90/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 94/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 98/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 102/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 106/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 110/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 114/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 118/122 kB&#xD;Progress (4): 87 kB | 25 kB | 14 kB | 122 kB    &#xD;                                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/2.0.9/maven-model-2.0.9.jar (87 kB at 578 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.0.9/maven-plugin-descriptor-2.0.9.jar&#xA;Progress (4): 25 kB | 14 kB | 122 kB | 4.1/29 kB&#xD;Progress (4): 25 kB | 14 kB | 122 kB | 7.7/29 kB&#xD;Progress (4): 25 kB | 14 kB | 122 kB | 12/29 kB &#xD;Progress (4): 25 kB | 14 kB | 122 kB | 16/29 kB&#xD;Progress (4): 25 kB | 14 kB | 122 kB | 20/29 kB&#xD;Progress (4): 25 kB | 14 kB | 122 kB | 24/29 kB&#xD;Progress (4): 25 kB | 14 kB | 122 kB | 28/29 kB&#xD;Progress (4): 25 kB | 14 kB | 122 kB | 29 kB   &#xD;                                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/2.0.9/maven-repository-metadata-2.0.9.jar (25 kB at 153 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.0.9/maven-artifact-manager-2.0.9.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-project/2.0.9/maven-project-2.0.9.jar (122 kB at 747 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.0.9/maven-monitor-2.0.9.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-error-diagnostics/2.0.9/maven-error-diagnostics-2.0.9.jar (14 kB at 82 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-toolchain/1.0/maven-toolchain-1.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-registry/2.0.9/maven-plugin-registry-2.0.9.jar (29 kB at 156 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-utils/0.1/maven-shared-utils-0.1.jar&#xA;Progress (1): 4.1/10 kB&#xD;Progress (1): 7.5/10 kB&#xD;Progress (1): 10 kB    &#xD;Progress (2): 10 kB | 4.1/155 kB&#xD;Progress (2): 10 kB | 7.7/155 kB&#xD;Progress (2): 10 kB | 12/155 kB &#xD;Progress (2): 10 kB | 16/155 kB&#xD;Progress (2): 10 kB | 20/155 kB&#xD;Progress (2): 10 kB | 24/155 kB&#xD;Progress (2): 10 kB | 28/155 kB&#xD;Progress (2): 10 kB | 32/155 kB&#xD;Progress (2): 10 kB | 36/155 kB&#xD;Progress (2): 10 kB | 40/155 kB&#xD;Progress (2): 10 kB | 45/155 kB&#xD;Progress (2): 10 kB | 49/155 kB&#xD;Progress (2): 10 kB | 53/155 kB&#xD;Progress (2): 10 kB | 57/155 kB&#xD;Progress (2): 10 kB | 61/155 kB&#xD;Progress (2): 10 kB | 65/155 kB&#xD;Progress (2): 10 kB | 69/155 kB&#xD;Progress (2): 10 kB | 73/155 kB&#xD;Progress (2): 10 kB | 77/155 kB&#xD;Progress (2): 10 kB | 81/155 kB&#xD;Progress (2): 10 kB | 86/155 kB&#xD;Progress (2): 10 kB | 90/155 kB&#xD;Progress (2): 10 kB | 94/155 kB&#xD;Progress (2): 10 kB | 98/155 kB&#xD;Progress (2): 10 kB | 102/155 kB&#xD;Progress (2): 10 kB | 106/155 kB&#xD;Progress (2): 10 kB | 110/155 kB&#xD;Progress (2): 10 kB | 114/155 kB&#xD;Progress (2): 10 kB | 118/155 kB&#xD;Progress (2): 10 kB | 122/155 kB&#xD;Progress (2): 10 kB | 126/155 kB&#xD;Progress (2): 10 kB | 131/155 kB&#xD;Progress (2): 10 kB | 135/155 kB&#xD;Progress (2): 10 kB | 139/155 kB&#xD;Progress (2): 10 kB | 143/155 kB&#xD;Progress (2): 10 kB | 147/155 kB&#xD;Progress (2): 10 kB | 151/155 kB&#xD;Progress (2): 10 kB | 155 kB    &#xD;Progress (3): 10 kB | 155 kB | 4.1/58 kB&#xD;Progress (3): 10 kB | 155 kB | 7.7/58 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 4.1/37 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 8.2/37 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 12/37 kB &#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 16/37 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 20/37 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 25/37 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 29/37 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 33/37 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 37/37 kB&#xD;Progress (4): 10 kB | 155 kB | 7.7/58 kB | 37 kB   &#xD;                                                &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-monitor/2.0.9/maven-monitor-2.0.9.jar (10 kB at 47 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/code/findbugs/jsr305/2.0.1/jsr305-2.0.1.jar&#xA;Progress (3): 155 kB | 12/58 kB | 37 kB&#xD;Progress (3): 155 kB | 16/58 kB | 37 kB&#xD;Progress (3): 155 kB | 20/58 kB | 37 kB&#xD;Progress (3): 155 kB | 24/58 kB | 37 kB&#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 4.1/33 kB&#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 7.7/33 kB&#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 12/33 kB &#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 16/33 kB&#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 20/33 kB&#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 24/33 kB&#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 28/33 kB&#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 32/33 kB&#xD;Progress (4): 155 kB | 24/58 kB | 37 kB | 33 kB   &#xD;Progress (4): 155 kB | 28/58 kB | 37 kB | 33 kB&#xD;Progress (4): 155 kB | 32/58 kB | 37 kB | 33 kB&#xD;Progress (4): 155 kB | 36/58 kB | 37 kB | 33 kB&#xD;Progress (4): 155 kB | 40/58 kB | 37 kB | 33 kB&#xD;                                               &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-utils/0.1/maven-shared-utils-0.1.jar (155 kB at 672 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-incremental/1.1/maven-shared-incremental-1.1.jar&#xA;Progress (3): 45/58 kB | 37 kB | 33 kB&#xD;Progress (3): 49/58 kB | 37 kB | 33 kB&#xD;Progress (3): 53/58 kB | 37 kB | 33 kB&#xD;Progress (3): 57/58 kB | 37 kB | 33 kB&#xD;Progress (3): 58 kB | 37 kB | 33 kB   &#xD;                                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-descriptor/2.0.9/maven-plugin-descriptor-2.0.9.jar (37 kB at 152 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-component-annotations/1.5.5/plexus-component-annotations-1.5.5.jar&#xA;Progress (3): 58 kB | 33 kB | 4.1/32 kB&#xD;Progress (3): 58 kB | 33 kB | 7.7/32 kB&#xD;Progress (3): 58 kB | 33 kB | 12/32 kB &#xD;Progress (3): 58 kB | 33 kB | 16/32 kB&#xD;Progress (3): 58 kB | 33 kB | 20/32 kB&#xD;Progress (3): 58 kB | 33 kB | 24/32 kB&#xD;Progress (3): 58 kB | 33 kB | 28/32 kB&#xD;Progress (3): 58 kB | 33 kB | 32 kB   &#xD;Progress (4): 58 kB | 33 kB | 32 kB | 4.1/14 kB&#xD;Progress (4): 58 kB | 33 kB | 32 kB | 7.7/14 kB&#xD;Progress (4): 58 kB | 33 kB | 32 kB | 12/14 kB &#xD;Progress (4): 58 kB | 33 kB | 32 kB | 14 kB   &#xD;                                           &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact-manager/2.0.9/maven-artifact-manager-2.0.9.jar (58 kB at 219 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-api/2.2/plexus-compiler-api-2.2.jar&#xA;Progress (4): 33 kB | 32 kB | 14 kB | 4.1/4.2 kB&#xD;Progress (4): 33 kB | 32 kB | 14 kB | 4.2 kB    &#xD;                                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-toolchain/1.0/maven-toolchain-1.0.jar (33 kB at 121 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-manager/2.2/plexus-compiler-manager-2.2.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-incremental/1.1/maven-shared-incremental-1.1.jar (14 kB at 48 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-javac/2.2/plexus-compiler-javac-2.2.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/code/findbugs/jsr305/2.0.1/jsr305-2.0.1.jar (32 kB at 112 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.5.5/plexus-container-default-1.5.5.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-component-annotations/1.5.5/plexus-component-annotations-1.5.5.jar (4.2 kB at 14 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-classworlds/2.2.2/plexus-classworlds-2.2.2.jar&#xA;Progress (1): 4.1/19 kB&#xD;Progress (1): 7.7/19 kB&#xD;Progress (1): 12/19 kB &#xD;Progress (1): 16/19 kB&#xD;Progress (1): 19 kB   &#xD;Progress (2): 19 kB | 4.1/4.6 kB&#xD;Progress (2): 19 kB | 4.6 kB    &#xD;Progress (3): 19 kB | 4.6 kB | 4.1/25 kB&#xD;Progress (3): 19 kB | 4.6 kB | 7.7/25 kB&#xD;Progress (3): 19 kB | 4.6 kB | 12/25 kB &#xD;Progress (3): 19 kB | 4.6 kB | 16/25 kB&#xD;Progress (3): 19 kB | 4.6 kB | 20/25 kB&#xD;Progress (3): 19 kB | 4.6 kB | 24/25 kB&#xD;Progress (3): 19 kB | 4.6 kB | 25 kB   &#xD;                                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-javac/2.2/plexus-compiler-javac-2.2.jar (19 kB at 58 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/xbean/xbean-reflect/3.4/xbean-reflect-3.4.jar&#xA;Progress (3): 4.6 kB | 25 kB | 4.1/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 7.7/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 12/134 kB &#xD;Progress (3): 4.6 kB | 25 kB | 16/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 20/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 24/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 28/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 32/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 36/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 40/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 45/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 49/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 53/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 57/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 61/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 65/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 69/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 73/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 77/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 81/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 86/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 90/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 94/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 98/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 102/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 106/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 110/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 114/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 118/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 122/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 126/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 131/134 kB&#xD;Progress (3): 4.6 kB | 25 kB | 134 kB    &#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 4.1/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 7.7/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 12/46 kB &#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 16/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 20/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 24/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 28/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 32/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 36/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 40/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 45/46 kB&#xD;Progress (4): 4.6 kB | 25 kB | 134 kB | 46 kB   &#xD;                                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-api/2.2/plexus-compiler-api-2.2.jar (25 kB at 70 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-compiler-manager/2.2/plexus-compiler-manager-2.2.jar (4.6 kB at 13 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/log4j/log4j/1.2.12/log4j-1.2.12.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-logging/commons-logging-api/1.1/commons-logging-api-1.1.jar&#xA;Progress (3): 134 kB | 46 kB | 4.1/217 kB&#xD;Progress (3): 134 kB | 46 kB | 7.7/217 kB&#xD;Progress (3): 134 kB | 46 kB | 12/217 kB &#xD;Progress (3): 134 kB | 46 kB | 16/217 kB&#xD;Progress (3): 134 kB | 46 kB | 20/217 kB&#xD;Progress (3): 134 kB | 46 kB | 24/217 kB&#xD;Progress (3): 134 kB | 46 kB | 28/217 kB&#xD;Progress (3): 134 kB | 46 kB | 32/217 kB&#xD;Progress (3): 134 kB | 46 kB | 36/217 kB&#xD;Progress (3): 134 kB | 46 kB | 40/217 kB&#xD;Progress (3): 134 kB | 46 kB | 45/217 kB&#xD;Progress (3): 134 kB | 46 kB | 49/217 kB&#xD;Progress (3): 134 kB | 46 kB | 53/217 kB&#xD;Progress (3): 134 kB | 46 kB | 57/217 kB&#xD;Progress (3): 134 kB | 46 kB | 61/217 kB&#xD;Progress (3): 134 kB | 46 kB | 65/217 kB&#xD;Progress (3): 134 kB | 46 kB | 69/217 kB&#xD;Progress (3): 134 kB | 46 kB | 73/217 kB&#xD;Progress (3): 134 kB | 46 kB | 77/217 kB&#xD;Progress (3): 134 kB | 46 kB | 81/217 kB&#xD;Progress (3): 134 kB | 46 kB | 86/217 kB&#xD;Progress (3): 134 kB | 46 kB | 90/217 kB&#xD;Progress (3): 134 kB | 46 kB | 94/217 kB&#xD;Progress (3): 134 kB | 46 kB | 98/217 kB&#xD;Progress (3): 134 kB | 46 kB | 102/217 kB&#xD;Progress (3): 134 kB | 46 kB | 106/217 kB&#xD;Progress (3): 134 kB | 46 kB | 110/217 kB&#xD;Progress (3): 134 kB | 46 kB | 114/217 kB&#xD;Progress (3): 134 kB | 46 kB | 118/217 kB&#xD;Progress (3): 134 kB | 46 kB | 122/217 kB&#xD;Progress (3): 134 kB | 46 kB | 126/217 kB&#xD;Progress (3): 134 kB | 46 kB | 131/217 kB&#xD;Progress (3): 134 kB | 46 kB | 135/217 kB&#xD;Progress (3): 134 kB | 46 kB | 139/217 kB&#xD;Progress (3): 134 kB | 46 kB | 143/217 kB&#xD;Progress (3): 134 kB | 46 kB | 147/217 kB&#xD;Progress (3): 134 kB | 46 kB | 151/217 kB&#xD;Progress (3): 134 kB | 46 kB | 155/217 kB&#xD;Progress (3): 134 kB | 46 kB | 159/217 kB&#xD;Progress (3): 134 kB | 46 kB | 163/217 kB&#xD;Progress (3): 134 kB | 46 kB | 167/217 kB&#xD;Progress (3): 134 kB | 46 kB | 172/217 kB&#xD;Progress (3): 134 kB | 46 kB | 176/217 kB&#xD;Progress (3): 134 kB | 46 kB | 180/217 kB&#xD;Progress (3): 134 kB | 46 kB | 184/217 kB&#xD;Progress (3): 134 kB | 46 kB | 188/217 kB&#xD;Progress (3): 134 kB | 46 kB | 192/217 kB&#xD;Progress (3): 134 kB | 46 kB | 196/217 kB&#xD;Progress (3): 134 kB | 46 kB | 200/217 kB&#xD;Progress (3): 134 kB | 46 kB | 204/217 kB&#xD;Progress (3): 134 kB | 46 kB | 208/217 kB&#xD;Progress (3): 134 kB | 46 kB | 212/217 kB&#xD;Progress (3): 134 kB | 46 kB | 217/217 kB&#xD;Progress (3): 134 kB | 46 kB | 217 kB    &#xD;                                     &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/xbean/xbean-reflect/3.4/xbean-reflect-3.4.jar (134 kB at 358 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/collections/google-collections/1.0/google-collections-1.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-classworlds/2.2.2/plexus-classworlds-2.2.2.jar (46 kB at 118 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/junit/junit/3.8.2/junit-3.8.2.jar&#xA;Progress (2): 217 kB | 4.1/640 kB&#xD;Progress (2): 217 kB | 7.7/640 kB&#xD;Progress (2): 217 kB | 12/640 kB &#xD;Progress (2): 217 kB | 16/640 kB&#xD;Progress (2): 217 kB | 20/640 kB&#xD;Progress (2): 217 kB | 24/640 kB&#xD;Progress (2): 217 kB | 28/640 kB&#xD;Progress (2): 217 kB | 32/640 kB&#xD;Progress (2): 217 kB | 36/640 kB&#xD;Progress (2): 217 kB | 40/640 kB&#xD;Progress (2): 217 kB | 45/640 kB&#xD;Progress (2): 217 kB | 49/640 kB&#xD;Progress (2): 217 kB | 53/640 kB&#xD;Progress (2): 217 kB | 57/640 kB&#xD;Progress (2): 217 kB | 61/640 kB&#xD;Progress (2): 217 kB | 65/640 kB&#xD;Progress (3): 217 kB | 65/640 kB | 4.1/45 kB&#xD;Progress (3): 217 kB | 69/640 kB | 4.1/45 kB&#xD;Progress (3): 217 kB | 69/640 kB | 7.7/45 kB&#xD;Progress (3): 217 kB | 73/640 kB | 7.7/45 kB&#xD;Progress (3): 217 kB | 73/640 kB | 12/45 kB &#xD;Progress (3): 217 kB | 77/640 kB | 12/45 kB&#xD;Progress (3): 217 kB | 77/640 kB | 16/45 kB&#xD;Progress (3): 217 kB | 81/640 kB | 16/45 kB&#xD;Progress (3): 217 kB | 85/640 kB | 16/45 kB&#xD;Progress (3): 217 kB | 89/640 kB | 16/45 kB&#xD;Progress (3): 217 kB | 89/640 kB | 20/45 kB&#xD;Progress (3): 217 kB | 93/640 kB | 20/45 kB&#xD;Progress (3): 217 kB | 93/640 kB | 24/45 kB&#xD;Progress (3): 217 kB | 98/640 kB | 24/45 kB&#xD;Progress (3): 217 kB | 98/640 kB | 28/45 kB&#xD;Progress (3): 217 kB | 98/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 102/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 106/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 110/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 114/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 118/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 122/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 126/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 130/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 134/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 139/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 143/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 147/640 kB | 32/45 kB&#xD;Progress (3): 217 kB | 147/640 kB | 36/45 kB&#xD;                                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.5.5/plexus-container-default-1.5.5.jar (217 kB at 528 kB/s)&#xA;Progress (2): 151/640 kB | 36/45 kB&#xD;Progress (2): 151/640 kB | 40/45 kB&#xD;Progress (2): 155/640 kB | 40/45 kB&#xD;Progress (2): 155/640 kB | 45/45 kB&#xD;Progress (2): 159/640 kB | 45/45 kB&#xD;Progress (2): 159/640 kB | 45 kB   &#xD;Progress (2): 163/640 kB | 45 kB&#xD;Progress (2): 167/640 kB | 45 kB&#xD;Progress (2): 171/640 kB | 45 kB&#xD;Progress (2): 175/640 kB | 45 kB&#xD;Progress (2): 179/640 kB | 45 kB&#xD;Progress (2): 184/640 kB | 45 kB&#xD;Progress (2): 188/640 kB | 45 kB&#xD;Progress (2): 192/640 kB | 45 kB&#xD;Progress (2): 196/640 kB | 45 kB&#xD;Progress (2): 200/640 kB | 45 kB&#xD;Progress (2): 204/640 kB | 45 kB&#xD;Progress (2): 208/640 kB | 45 kB&#xD;Progress (2): 212/640 kB | 45 kB&#xD;Progress (2): 216/640 kB | 45 kB&#xD;Progress (2): 220/640 kB | 45 kB&#xD;Progress (2): 225/640 kB | 45 kB&#xD;Progress (2): 229/640 kB | 45 kB&#xD;Progress (2): 233/640 kB | 45 kB&#xD;Progress (2): 237/640 kB | 45 kB&#xD;Progress (2): 241/640 kB | 45 kB&#xD;Progress (2): 245/640 kB | 45 kB&#xD;Progress (2): 249/640 kB | 45 kB&#xD;Progress (2): 253/640 kB | 45 kB&#xD;Progress (2): 257/640 kB | 45 kB&#xD;Progress (2): 261/640 kB | 45 kB&#xD;Progress (2): 266/640 kB | 45 kB&#xD;Progress (2): 270/640 kB | 45 kB&#xD;Progress (2): 274/640 kB | 45 kB&#xD;Progress (2): 278/640 kB | 45 kB&#xD;Progress (2): 282/640 kB | 45 kB&#xD;Progress (2): 286/640 kB | 45 kB&#xD;Progress (2): 290/640 kB | 45 kB&#xD;Progress (2): 294/640 kB | 45 kB&#xD;Progress (2): 298/640 kB | 45 kB&#xD;Progress (2): 302/640 kB | 45 kB&#xD;Progress (2): 306/640 kB | 45 kB&#xD;Progress (2): 311/640 kB | 45 kB&#xD;Progress (2): 315/640 kB | 45 kB&#xD;Progress (2): 319/640 kB | 45 kB&#xD;Progress (2): 323/640 kB | 45 kB&#xD;Progress (2): 327/640 kB | 45 kB&#xD;Progress (2): 331/640 kB | 45 kB&#xD;Progress (2): 335/640 kB | 45 kB&#xD;Progress (2): 339/640 kB | 45 kB&#xD;Progress (2): 343/640 kB | 45 kB&#xD;Progress (2): 347/640 kB | 45 kB&#xD;Progress (2): 352/640 kB | 45 kB&#xD;Progress (2): 356/640 kB | 45 kB&#xD;Progress (2): 360/640 kB | 45 kB&#xD;Progress (2): 364/640 kB | 45 kB&#xD;Progress (2): 368/640 kB | 45 kB&#xD;Progress (2): 372/640 kB | 45 kB&#xD;Progress (2): 376/640 kB | 45 kB&#xD;Progress (2): 380/640 kB | 45 kB&#xD;Progress (2): 384/640 kB | 45 kB&#xD;Progress (2): 388/640 kB | 45 kB&#xD;Progress (2): 392/640 kB | 45 kB&#xD;Progress (2): 397/640 kB | 45 kB&#xD;Progress (2): 401/640 kB | 45 kB&#xD;Progress (2): 405/640 kB | 45 kB&#xD;Progress (2): 409/640 kB | 45 kB&#xD;Progress (2): 413/640 kB | 45 kB&#xD;Progress (2): 417/640 kB | 45 kB&#xD;Progress (2): 421/640 kB | 45 kB&#xD;Progress (2): 425/640 kB | 45 kB&#xD;Progress (2): 429/640 kB | 45 kB&#xD;Progress (2): 433/640 kB | 45 kB&#xD;Progress (2): 438/640 kB | 45 kB&#xD;Progress (2): 442/640 kB | 45 kB&#xD;Progress (2): 446/640 kB | 45 kB&#xD;Progress (2): 450/640 kB | 45 kB&#xD;Progress (2): 454/640 kB | 45 kB&#xD;Progress (2): 458/640 kB | 45 kB&#xD;Progress (2): 462/640 kB | 45 kB&#xD;Progress (2): 466/640 kB | 45 kB&#xD;Progress (2): 470/640 kB | 45 kB&#xD;Progress (2): 474/640 kB | 45 kB&#xD;Progress (2): 479/640 kB | 45 kB&#xD;Progress (2): 483/640 kB | 45 kB&#xD;Progress (2): 487/640 kB | 45 kB&#xD;Progress (2): 491/640 kB | 45 kB&#xD;Progress (2): 495/640 kB | 45 kB&#xD;Progress (2): 498/640 kB | 45 kB&#xD;Progress (2): 502/640 kB | 45 kB&#xD;Progress (2): 506/640 kB | 45 kB&#xD;Progress (2): 510/640 kB | 45 kB&#xD;Progress (2): 514/640 kB | 45 kB&#xD;Progress (2): 518/640 kB | 45 kB&#xD;Progress (2): 522/640 kB | 45 kB&#xD;Progress (2): 526/640 kB | 45 kB&#xD;Progress (2): 531/640 kB | 45 kB&#xD;Progress (2): 535/640 kB | 45 kB&#xD;Progress (2): 539/640 kB | 45 kB&#xD;Progress (2): 543/640 kB | 45 kB&#xD;Progress (2): 547/640 kB | 45 kB&#xD;Progress (2): 551/640 kB | 45 kB&#xD;Progress (2): 555/640 kB | 45 kB&#xD;Progress (2): 559/640 kB | 45 kB&#xD;Progress (2): 563/640 kB | 45 kB&#xD;Progress (2): 567/640 kB | 45 kB&#xD;Progress (2): 572/640 kB | 45 kB&#xD;Progress (2): 576/640 kB | 45 kB&#xD;Progress (2): 580/640 kB | 45 kB&#xD;Progress (2): 584/640 kB | 45 kB&#xD;Progress (2): 588/640 kB | 45 kB&#xD;Progress (2): 592/640 kB | 45 kB&#xD;Progress (2): 596/640 kB | 45 kB&#xD;Progress (2): 600/640 kB | 45 kB&#xD;Progress (2): 604/640 kB | 45 kB&#xD;Progress (2): 608/640 kB | 45 kB&#xD;Progress (2): 612/640 kB | 45 kB&#xD;Progress (2): 617/640 kB | 45 kB&#xD;Progress (2): 621/640 kB | 45 kB&#xD;Progress (2): 625/640 kB | 45 kB&#xD;Progress (2): 629/640 kB | 45 kB&#xD;Progress (2): 633/640 kB | 45 kB&#xD;Progress (2): 637/640 kB | 45 kB&#xD;Progress (2): 640 kB | 45 kB    &#xD;Progress (3): 640 kB | 45 kB | 4.1/121 kB&#xD;Progress (3): 640 kB | 45 kB | 7.7/121 kB&#xD;Progress (3): 640 kB | 45 kB | 12/121 kB &#xD;Progress (3): 640 kB | 45 kB | 16/121 kB&#xD;Progress (3): 640 kB | 45 kB | 20/121 kB&#xD;Progress (3): 640 kB | 45 kB | 24/121 kB&#xD;Progress (3): 640 kB | 45 kB | 28/121 kB&#xD;Progress (3): 640 kB | 45 kB | 32/121 kB&#xD;Progress (3): 640 kB | 45 kB | 36/121 kB&#xD;Progress (3): 640 kB | 45 kB | 40/121 kB&#xD;Progress (3): 640 kB | 45 kB | 45/121 kB&#xD;Progress (3): 640 kB | 45 kB | 49/121 kB&#xD;Progress (3): 640 kB | 45 kB | 53/121 kB&#xD;Progress (3): 640 kB | 45 kB | 57/121 kB&#xD;Progress (3): 640 kB | 45 kB | 61/121 kB&#xD;Progress (3): 640 kB | 45 kB | 65/121 kB&#xD;Progress (3): 640 kB | 45 kB | 69/121 kB&#xD;Progress (3): 640 kB | 45 kB | 73/121 kB&#xD;Progress (3): 640 kB | 45 kB | 77/121 kB&#xD;Progress (3): 640 kB | 45 kB | 81/121 kB&#xD;Progress (3): 640 kB | 45 kB | 86/121 kB&#xD;Progress (3): 640 kB | 45 kB | 90/121 kB&#xD;Progress (3): 640 kB | 45 kB | 94/121 kB&#xD;Progress (3): 640 kB | 45 kB | 98/121 kB&#xD;Progress (3): 640 kB | 45 kB | 102/121 kB&#xD;Progress (3): 640 kB | 45 kB | 106/121 kB&#xD;Progress (3): 640 kB | 45 kB | 110/121 kB&#xD;Progress (3): 640 kB | 45 kB | 114/121 kB&#xD;Progress (3): 640 kB | 45 kB | 118/121 kB&#xD;Progress (3): 640 kB | 45 kB | 121 kB    &#xD;                                     &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/collections/google-collections/1.0/google-collections-1.0.jar (640 kB at 1.5 MB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/junit/junit/3.8.2/junit-3.8.2.jar (121 kB at 264 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/commons-logging/commons-logging-api/1.1/commons-logging-api-1.1.jar (45 kB at 97 kB/s)&#xA;Progress (1): 4.1/358 kB&#xD;Progress (1): 8.2/358 kB&#xD;Progress (1): 12/358 kB &#xD;Progress (1): 16/358 kB&#xD;Progress (1): 20/358 kB&#xD;Progress (1): 25/358 kB&#xD;Progress (1): 29/358 kB&#xD;Progress (1): 33/358 kB&#xD;Progress (1): 37/358 kB&#xD;Progress (1): 41/358 kB&#xD;Progress (1): 45/358 kB&#xD;Progress (1): 49/358 kB&#xD;Progress (1): 53/358 kB&#xD;Progress (1): 57/358 kB&#xD;Progress (1): 61/358 kB&#xD;Progress (1): 66/358 kB&#xD;Progress (1): 70/358 kB&#xD;Progress (1): 74/358 kB&#xD;Progress (1): 78/358 kB&#xD;Progress (1): 82/358 kB&#xD;Progress (1): 86/358 kB&#xD;Progress (1): 90/358 kB&#xD;Progress (1): 94/358 kB&#xD;Progress (1): 98/358 kB&#xD;Progress (1): 102/358 kB&#xD;Progress (1): 106/358 kB&#xD;Progress (1): 111/358 kB&#xD;Progress (1): 115/358 kB&#xD;Progress (1): 119/358 kB&#xD;Progress (1): 123/358 kB&#xD;Progress (1): 127/358 kB&#xD;Progress (1): 131/358 kB&#xD;Progress (1): 135/358 kB&#xD;Progress (1): 139/358 kB&#xD;Progress (1): 143/358 kB&#xD;Progress (1): 147/358 kB&#xD;Progress (1): 152/358 kB&#xD;Progress (1): 156/358 kB&#xD;Progress (1): 160/358 kB&#xD;Progress (1): 164/358 kB&#xD;Progress (1): 168/358 kB&#xD;Progress (1): 172/358 kB&#xD;Progress (1): 176/358 kB&#xD;Progress (1): 180/358 kB&#xD;Progress (1): 184/358 kB&#xD;Progress (1): 188/358 kB&#xD;Progress (1): 193/358 kB&#xD;Progress (1): 197/358 kB&#xD;Progress (1): 201/358 kB&#xD;Progress (1): 205/358 kB&#xD;Progress (1): 209/358 kB&#xD;Progress (1): 213/358 kB&#xD;Progress (1): 217/358 kB&#xD;Progress (1): 221/358 kB&#xD;Progress (1): 225/358 kB&#xD;Progress (1): 229/358 kB&#xD;Progress (1): 233/358 kB&#xD;Progress (1): 238/358 kB&#xD;Progress (1): 242/358 kB&#xD;Progress (1): 246/358 kB&#xD;Progress (1): 250/358 kB&#xD;Progress (1): 254/358 kB&#xD;Progress (1): 258/358 kB&#xD;Progress (1): 262/358 kB&#xD;Progress (1): 266/358 kB&#xD;Progress (1): 270/358 kB&#xD;Progress (1): 274/358 kB&#xD;Progress (1): 279/358 kB&#xD;Progress (1): 283/358 kB&#xD;Progress (1): 287/358 kB&#xD;Progress (1): 291/358 kB&#xD;Progress (1): 295/358 kB&#xD;Progress (1): 299/358 kB&#xD;Progress (1): 303/358 kB&#xD;Progress (1): 307/358 kB&#xD;Progress (1): 311/358 kB&#xD;Progress (1): 315/358 kB&#xD;Progress (1): 319/358 kB&#xD;Progress (1): 324/358 kB&#xD;Progress (1): 328/358 kB&#xD;Progress (1): 332/358 kB&#xD;Progress (1): 336/358 kB&#xD;Progress (1): 340/358 kB&#xD;Progress (1): 344/358 kB&#xD;Progress (1): 348/358 kB&#xD;Progress (1): 352/358 kB&#xD;Progress (1): 356/358 kB&#xD;Progress (1): 358 kB    &#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/log4j/log4j/1.2.12/log4j-1.2.12.jar (358 kB at 409 kB/s)&#xA;[INFO] Changes detected - recompiling the module!&#xA;[WARNING] File encoding has not been set, using platform encoding UTF-8, i.e. build is platform dependent!&#xA;[INFO] Compiling 1 source file to /work/target/classes&#xA;[INFO] &#xA;[INFO] --- maven-resources-plugin:2.6:testResources (default-testResources) @ simple-java-project ---&#xA;[WARNING] Using platform encoding (UTF-8 actually) to copy filtered resources, i.e. build is platform dependent!&#xA;[INFO] skip non existing resourceDirectory /work/src/test/resources&#xA;[INFO] &#xA;[INFO] --- maven-compiler-plugin:3.1:testCompile (default-testCompile) @ simple-java-project ---&#xA;[INFO] No sources to compile&#xA;[INFO] &#xA;[INFO] --- maven-surefire-plugin:2.12.4:test (default-test) @ simple-java-project ---&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire-booter/2.12.4/surefire-booter-2.12.4.pom&#xA;Progress (1): 3.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire-booter/2.12.4/surefire-booter-2.12.4.pom (3.0 kB at 33 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire-api/2.12.4/surefire-api-2.12.4.pom&#xA;Progress (1): 2.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire-api/2.12.4/surefire-api-2.12.4.pom (2.5 kB at 24 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/maven-surefire-common/2.12.4/maven-surefire-common-2.12.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/maven-surefire-common/2.12.4/maven-surefire-common-2.12.4.pom (5.5 kB at 61 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugin-tools/maven-plugin-annotations/3.1/maven-plugin-annotations-3.1.pom&#xA;Progress (1): 1.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugin-tools/maven-plugin-annotations/3.1/maven-plugin-annotations-3.1.pom (1.6 kB at 24 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugin-tools/maven-plugin-tools/3.1/maven-plugin-tools-3.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugin-tools/maven-plugin-tools/3.1/maven-plugin-tools-3.1.pom (16 kB at 180 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting-api/2.0.9/maven-reporting-api-2.0.9.pom&#xA;Progress (1): 1.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting-api/2.0.9/maven-reporting-api-2.0.9.pom (1.8 kB at 21 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting/2.0.9/maven-reporting-2.0.9.pom&#xA;Progress (1): 1.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting/2.0.9/maven-reporting-2.0.9.pom (1.5 kB at 19 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-toolchain/2.0.9/maven-toolchain-2.0.9.pom&#xA;Progress (1): 3.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-toolchain/2.0.9/maven-toolchain-2.0.9.pom (3.5 kB at 58 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-lang3/3.1/commons-lang3-3.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 17 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-lang3/3.1/commons-lang3-3.1.pom (17 kB at 288 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-parent/22/commons-parent-22.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 42 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-parent/22/commons-parent-22.pom (42 kB at 791 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/9/apache-9.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 15 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/9/apache-9.pom (15 kB at 178 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-common-artifact-filters/1.3/maven-common-artifact-filters-1.3.pom&#xA;Progress (1): 3.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-common-artifact-filters/1.3/maven-common-artifact-filters-1.3.pom (3.7 kB at 33 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/12/maven-shared-components-12.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 9.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/12/maven-shared-components-12.pom (9.3 kB at 109 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/13/maven-parent-13.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 23 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/13/maven-parent-13.pom (23 kB at 343 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/6/apache-6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 13 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/6/apache-6.pom (13 kB at 206 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.0-alpha-9/plexus-container-default-1.0-alpha-9.pom&#xA;Progress (1): 1.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-container-default/1.0-alpha-9/plexus-container-default-1.0-alpha-9.pom (1.2 kB at 18 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire-booter/2.12.4/surefire-booter-2.12.4.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire-api/2.12.4/surefire-api-2.12.4.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/maven-surefire-common/2.12.4/maven-surefire-common-2.12.4.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-lang3/3.1/commons-lang3-3.1.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-common-artifact-filters/1.3/maven-common-artifact-filters-1.3.jar&#xA;Progress (1): 4.1/263 kB&#xD;Progress (1): 7.7/263 kB&#xD;Progress (1): 12/263 kB &#xD;Progress (1): 16/263 kB&#xD;Progress (1): 20/263 kB&#xD;Progress (1): 24/263 kB&#xD;Progress (1): 28/263 kB&#xD;Progress (1): 32/263 kB&#xD;Progress (1): 36/263 kB&#xD;Progress (1): 40/263 kB&#xD;Progress (1): 45/263 kB&#xD;Progress (1): 49/263 kB&#xD;Progress (1): 53/263 kB&#xD;Progress (1): 57/263 kB&#xD;Progress (1): 61/263 kB&#xD;Progress (1): 65/263 kB&#xD;Progress (1): 69/263 kB&#xD;Progress (1): 73/263 kB&#xD;Progress (1): 77/263 kB&#xD;Progress (1): 81/263 kB&#xD;Progress (2): 81/263 kB | 4.1/316 kB&#xD;Progress (2): 86/263 kB | 4.1/316 kB&#xD;Progress (2): 86/263 kB | 7.7/316 kB&#xD;Progress (2): 90/263 kB | 7.7/316 kB&#xD;Progress (2): 94/263 kB | 7.7/316 kB&#xD;Progress (2): 98/263 kB | 7.7/316 kB&#xD;Progress (2): 98/263 kB | 12/316 kB &#xD;Progress (2): 98/263 kB | 16/316 kB&#xD;Progress (2): 102/263 kB | 16/316 kB&#xD;Progress (2): 102/263 kB | 20/316 kB&#xD;Progress (2): 106/263 kB | 20/316 kB&#xD;Progress (2): 106/263 kB | 24/316 kB&#xD;Progress (2): 110/263 kB | 24/316 kB&#xD;Progress (2): 114/263 kB | 24/316 kB&#xD;Progress (2): 114/263 kB | 28/316 kB&#xD;Progress (2): 114/263 kB | 32/316 kB&#xD;Progress (2): 114/263 kB | 36/316 kB&#xD;Progress (2): 114/263 kB | 40/316 kB&#xD;Progress (2): 114/263 kB | 45/316 kB&#xD;Progress (2): 114/263 kB | 49/316 kB&#xD;Progress (2): 114/263 kB | 53/316 kB&#xD;Progress (2): 114/263 kB | 57/316 kB&#xD;Progress (2): 114/263 kB | 61/316 kB&#xD;Progress (2): 114/263 kB | 65/316 kB&#xD;Progress (2): 114/263 kB | 69/316 kB&#xD;Progress (2): 114/263 kB | 73/316 kB&#xD;Progress (2): 114/263 kB | 77/316 kB&#xD;Progress (2): 114/263 kB | 81/316 kB&#xD;Progress (2): 118/263 kB | 81/316 kB&#xD;Progress (2): 118/263 kB | 86/316 kB&#xD;Progress (2): 122/263 kB | 86/316 kB&#xD;Progress (2): 122/263 kB | 90/316 kB&#xD;Progress (2): 126/263 kB | 90/316 kB&#xD;Progress (2): 131/263 kB | 90/316 kB&#xD;Progress (2): 131/263 kB | 94/316 kB&#xD;Progress (2): 135/263 kB | 94/316 kB&#xD;Progress (2): 135/263 kB | 98/316 kB&#xD;Progress (2): 135/263 kB | 102/316 kB&#xD;Progress (2): 135/263 kB | 106/316 kB&#xD;Progress (2): 139/263 kB | 106/316 kB&#xD;Progress (2): 139/263 kB | 110/316 kB&#xD;Progress (2): 143/263 kB | 110/316 kB&#xD;Progress (2): 143/263 kB | 114/316 kB&#xD;Progress (2): 147/263 kB | 114/316 kB&#xD;Progress (2): 147/263 kB | 118/316 kB&#xD;Progress (2): 147/263 kB | 122/316 kB&#xD;Progress (2): 151/263 kB | 122/316 kB&#xD;Progress (2): 151/263 kB | 126/316 kB&#xD;Progress (2): 155/263 kB | 126/316 kB&#xD;Progress (2): 155/263 kB | 131/316 kB&#xD;Progress (2): 159/263 kB | 131/316 kB&#xD;Progress (2): 159/263 kB | 135/316 kB&#xD;Progress (2): 163/263 kB | 135/316 kB&#xD;Progress (2): 163/263 kB | 139/316 kB&#xD;Progress (2): 163/263 kB | 143/316 kB&#xD;Progress (2): 163/263 kB | 147/316 kB&#xD;Progress (2): 163/263 kB | 151/316 kB&#xD;Progress (2): 163/263 kB | 155/316 kB&#xD;Progress (2): 163/263 kB | 159/316 kB&#xD;Progress (2): 163/263 kB | 163/316 kB&#xD;Progress (2): 163/263 kB | 167/316 kB&#xD;Progress (2): 163/263 kB | 172/316 kB&#xD;Progress (2): 163/263 kB | 176/316 kB&#xD;Progress (2): 163/263 kB | 180/316 kB&#xD;Progress (2): 163/263 kB | 184/316 kB&#xD;Progress (2): 163/263 kB | 188/316 kB&#xD;Progress (2): 163/263 kB | 192/316 kB&#xD;Progress (2): 163/263 kB | 196/316 kB&#xD;Progress (2): 163/263 kB | 200/316 kB&#xD;Progress (2): 163/263 kB | 204/316 kB&#xD;Progress (2): 167/263 kB | 204/316 kB&#xD;Progress (2): 167/263 kB | 208/316 kB&#xD;Progress (2): 172/263 kB | 208/316 kB&#xD;Progress (2): 172/263 kB | 213/316 kB&#xD;Progress (2): 176/263 kB | 213/316 kB&#xD;Progress (2): 176/263 kB | 217/316 kB&#xD;Progress (2): 180/263 kB | 217/316 kB&#xD;Progress (2): 180/263 kB | 221/316 kB&#xD;Progress (2): 180/263 kB | 225/316 kB&#xD;Progress (2): 184/263 kB | 225/316 kB&#xD;Progress (2): 184/263 kB | 229/316 kB&#xD;Progress (2): 188/263 kB | 229/316 kB&#xD;Progress (2): 188/263 kB | 233/316 kB&#xD;Progress (2): 192/263 kB | 233/316 kB&#xD;Progress (2): 192/263 kB | 237/316 kB&#xD;Progress (2): 196/263 kB | 237/316 kB&#xD;Progress (2): 196/263 kB | 241/316 kB&#xD;Progress (2): 200/263 kB | 241/316 kB&#xD;Progress (2): 200/263 kB | 245/316 kB&#xD;Progress (2): 204/263 kB | 245/316 kB&#xD;Progress (2): 204/263 kB | 249/316 kB&#xD;Progress (2): 208/263 kB | 249/316 kB&#xD;Progress (2): 208/263 kB | 253/316 kB&#xD;Progress (2): 213/263 kB | 253/316 kB&#xD;Progress (2): 213/263 kB | 258/316 kB&#xD;Progress (2): 213/263 kB | 262/316 kB&#xD;Progress (2): 213/263 kB | 266/316 kB&#xD;Progress (2): 213/263 kB | 270/316 kB&#xD;Progress (2): 213/263 kB | 274/316 kB&#xD;Progress (2): 213/263 kB | 278/316 kB&#xD;Progress (2): 213/263 kB | 282/316 kB&#xD;Progress (2): 213/263 kB | 286/316 kB&#xD;Progress (2): 213/263 kB | 290/316 kB&#xD;Progress (2): 213/263 kB | 294/316 kB&#xD;Progress (2): 213/263 kB | 299/316 kB&#xD;Progress (2): 213/263 kB | 303/316 kB&#xD;Progress (2): 213/263 kB | 307/316 kB&#xD;Progress (2): 213/263 kB | 311/316 kB&#xD;Progress (2): 213/263 kB | 315/316 kB&#xD;Progress (2): 213/263 kB | 316 kB    &#xD;Progress (2): 217/263 kB | 316 kB&#xD;Progress (2): 221/263 kB | 316 kB&#xD;Progress (2): 225/263 kB | 316 kB&#xD;Progress (2): 229/263 kB | 316 kB&#xD;Progress (2): 233/263 kB | 316 kB&#xD;Progress (2): 237/263 kB | 316 kB&#xD;Progress (2): 241/263 kB | 316 kB&#xD;Progress (2): 245/263 kB | 316 kB&#xD;Progress (2): 249/263 kB | 316 kB&#xD;Progress (2): 253/263 kB | 316 kB&#xD;Progress (2): 258/263 kB | 316 kB&#xD;Progress (2): 262/263 kB | 316 kB&#xD;Progress (2): 263 kB | 316 kB    &#xD;Progress (3): 263 kB | 316 kB | 4.1/31 kB&#xD;Progress (3): 263 kB | 316 kB | 7.7/31 kB&#xD;Progress (3): 263 kB | 316 kB | 12/31 kB &#xD;Progress (3): 263 kB | 316 kB | 16/31 kB&#xD;Progress (3): 263 kB | 316 kB | 20/31 kB&#xD;Progress (3): 263 kB | 316 kB | 24/31 kB&#xD;Progress (3): 263 kB | 316 kB | 28/31 kB&#xD;Progress (3): 263 kB | 316 kB | 31 kB   &#xD;Progress (4): 263 kB | 316 kB | 31 kB | 4.1/35 kB&#xD;Progress (4): 263 kB | 316 kB | 31 kB | 7.7/35 kB&#xD;Progress (4): 263 kB | 316 kB | 31 kB | 12/35 kB &#xD;Progress (4): 263 kB | 316 kB | 31 kB | 16/35 kB&#xD;Progress (4): 263 kB | 316 kB | 31 kB | 20/35 kB&#xD;Progress (4): 263 kB | 316 kB | 31 kB | 24/35 kB&#xD;Progress (4): 263 kB | 316 kB | 31 kB | 28/35 kB&#xD;Progress (4): 263 kB | 316 kB | 31 kB | 32/35 kB&#xD;Progress (4): 263 kB | 316 kB | 31 kB | 35 kB   &#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 4.1/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 7.7/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 12/118 kB &#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 16/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 20/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 24/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 28/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 32/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 36/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 40/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 45/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 49/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 53/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 57/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 61/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 65/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 69/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 73/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 77/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 81/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 86/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 90/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 94/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 98/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 102/118 kB&#xD;Progress (5): 263 kB | 316 kB | 31 kB | 35 kB | 106/118 kB&#xD;                                                          &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/maven-surefire-common/2.12.4/maven-surefire-common-2.12.4.jar (263 kB at 5.1 MB/s)&#xA;Progress (4): 316 kB | 31 kB | 35 kB | 110/118 kB&#xD;                                                 &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.0.8/plexus-utils-3.0.8.jar&#xA;Progress (4): 316 kB | 31 kB | 35 kB | 114/118 kB&#xD;Progress (4): 316 kB | 31 kB | 35 kB | 118 kB    &#xD;                                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-lang3/3.1/commons-lang3-3.1.jar (316 kB at 6.1 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting-api/2.0.9/maven-reporting-api-2.0.9.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-common-artifact-filters/1.3/maven-common-artifact-filters-1.3.jar (31 kB at 586 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-toolchain/2.0.9/maven-toolchain-2.0.9.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire-booter/2.12.4/surefire-booter-2.12.4.jar (35 kB at 588 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugin-tools/maven-plugin-annotations/3.1/maven-plugin-annotations-3.1.jar&#xA;Progress (2): 118 kB | 4.1/10 kB&#xD;Progress (2): 118 kB | 7.7/10 kB&#xD;Progress (2): 118 kB | 10 kB    &#xD;Progress (3): 118 kB | 10 kB | 4.1/38 kB&#xD;Progress (3): 118 kB | 10 kB | 7.7/38 kB&#xD;Progress (3): 118 kB | 10 kB | 12/38 kB &#xD;Progress (3): 118 kB | 10 kB | 16/38 kB&#xD;Progress (3): 118 kB | 10 kB | 20/38 kB&#xD;Progress (3): 118 kB | 10 kB | 24/38 kB&#xD;Progress (3): 118 kB | 10 kB | 28/38 kB&#xD;Progress (3): 118 kB | 10 kB | 32/38 kB&#xD;Progress (3): 118 kB | 10 kB | 36/38 kB&#xD;Progress (3): 118 kB | 10 kB | 38 kB   &#xD;                                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/surefire/surefire-api/2.12.4/surefire-api-2.12.4.jar (118 kB at 1.5 MB/s)&#xA;Progress (3): 10 kB | 38 kB | 4.1/232 kB&#xD;Progress (3): 10 kB | 38 kB | 8.2/232 kB&#xD;Progress (3): 10 kB | 38 kB | 12/232 kB &#xD;Progress (3): 10 kB | 38 kB | 16/232 kB&#xD;Progress (3): 10 kB | 38 kB | 20/232 kB&#xD;Progress (3): 10 kB | 38 kB | 25/232 kB&#xD;Progress (3): 10 kB | 38 kB | 29/232 kB&#xD;Progress (3): 10 kB | 38 kB | 33/232 kB&#xD;Progress (3): 10 kB | 38 kB | 37/232 kB&#xD;Progress (3): 10 kB | 38 kB | 41/232 kB&#xD;Progress (3): 10 kB | 38 kB | 45/232 kB&#xD;Progress (3): 10 kB | 38 kB | 49/232 kB&#xD;Progress (3): 10 kB | 38 kB | 53/232 kB&#xD;Progress (3): 10 kB | 38 kB | 57/232 kB&#xD;Progress (3): 10 kB | 38 kB | 61/232 kB&#xD;Progress (3): 10 kB | 38 kB | 66/232 kB&#xD;Progress (3): 10 kB | 38 kB | 70/232 kB&#xD;Progress (3): 10 kB | 38 kB | 74/232 kB&#xD;Progress (3): 10 kB | 38 kB | 78/232 kB&#xD;Progress (3): 10 kB | 38 kB | 82/232 kB&#xD;Progress (3): 10 kB | 38 kB | 86/232 kB&#xD;Progress (3): 10 kB | 38 kB | 90/232 kB&#xD;Progress (3): 10 kB | 38 kB | 94/232 kB&#xD;Progress (4): 10 kB | 38 kB | 94/232 kB | 4.1/14 kB&#xD;Progress (4): 10 kB | 38 kB | 98/232 kB | 4.1/14 kB&#xD;Progress (4): 10 kB | 38 kB | 102/232 kB | 4.1/14 kB&#xD;Progress (4): 10 kB | 38 kB | 102/232 kB | 7.7/14 kB&#xD;Progress (4): 10 kB | 38 kB | 106/232 kB | 7.7/14 kB&#xD;Progress (4): 10 kB | 38 kB | 111/232 kB | 7.7/14 kB&#xD;Progress (4): 10 kB | 38 kB | 115/232 kB | 7.7/14 kB&#xD;Progress (4): 10 kB | 38 kB | 115/232 kB | 12/14 kB &#xD;Progress (4): 10 kB | 38 kB | 119/232 kB | 12/14 kB&#xD;Progress (4): 10 kB | 38 kB | 119/232 kB | 14 kB   &#xD;Progress (4): 10 kB | 38 kB | 123/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 127/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 131/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 135/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 139/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 143/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 147/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 152/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 156/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 160/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 164/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 168/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 172/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 176/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 180/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 184/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 188/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 193/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 197/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 201/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 205/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 209/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 213/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 217/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 221/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 225/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 229/232 kB | 14 kB&#xD;Progress (4): 10 kB | 38 kB | 232 kB | 14 kB    &#xD;                                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/reporting/maven-reporting-api/2.0.9/maven-reporting-api-2.0.9.jar (10 kB at 106 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-toolchain/2.0.9/maven-toolchain-2.0.9.jar (38 kB at 391 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.0.8/plexus-utils-3.0.8.jar (232 kB at 2.2 MB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugin-tools/maven-plugin-annotations/3.1/maven-plugin-annotations-3.1.jar (14 kB at 118 kB/s)&#xA;[INFO] Tests are skipped.&#xA;[INFO] &#xA;[INFO] --- maven-jar-plugin:3.3.0:jar (default-jar) @ simple-java-project ---&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/file-management/3.1.0/file-management-3.1.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/file-management/3.1.0/file-management-3.1.0.pom (4.5 kB at 88 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/36/maven-shared-components-36.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/36/maven-shared-components-36.pom (4.9 kB at 91 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/36/maven-parent-36.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 45 kB&#xD;Progress (1): 45 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/36/maven-parent-36.pom (45 kB at 1.0 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/26/apache-26.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 21 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/26/apache-26.pom (21 kB at 270 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.pom&#xA;Progress (1): 2.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.pom (2.7 kB at 46 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-parent/1.7.36/slf4j-parent-1.7.36.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 14 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-parent/1.7.36/slf4j-parent-1.7.36.pom (14 kB at 239 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.3.0/plexus-utils-3.3.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.3.0/plexus-utils-3.3.0.pom (5.2 kB at 72 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/5.1/plexus-5.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 23 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/5.1/plexus-5.1.pom (23 kB at 341 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.11.0/commons-io-2.11.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.11.0/commons-io-2.11.0.pom (20 kB at 270 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-parent/52/commons-parent-52.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 45 kB&#xD;Progress (1): 49 kB&#xD;Progress (1): 53 kB&#xD;Progress (1): 57 kB&#xD;Progress (1): 61 kB&#xD;Progress (1): 66 kB&#xD;Progress (1): 70 kB&#xD;Progress (1): 74 kB&#xD;Progress (1): 78 kB&#xD;Progress (1): 79 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-parent/52/commons-parent-52.pom (79 kB at 1.3 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/junit/junit-bom/5.7.2/junit-bom-5.7.2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/junit/junit-bom/5.7.2/junit-bom-5.7.2.pom (5.1 kB at 55 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-archiver/3.6.0/maven-archiver-3.6.0.pom&#xA;Progress (1): 3.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-archiver/3.6.0/maven-archiver-3.6.0.pom (3.9 kB at 62 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-io/3.4.0/plexus-io-3.4.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-io/3.4.0/plexus-io-3.4.0.pom (6.0 kB at 95 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/10/plexus-10.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 25 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/10/plexus-10.pom (25 kB at 358 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/javax/inject/javax.inject/1/javax.inject-1.pom&#xA;Progress (1): 612 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/javax/inject/javax.inject/1/javax.inject-1.pom (612 B at 7.7 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-archiver/4.4.0/plexus-archiver-4.4.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-archiver/4.4.0/plexus-archiver-4.4.0.pom (6.3 kB at 81 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-compress/1.21/commons-compress-1.21.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-compress/1.21/commons-compress-1.21.pom (20 kB at 277 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/iq80/snappy/snappy/0.4/snappy-0.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 15 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/iq80/snappy/snappy/0.4/snappy-0.4.pom (15 kB at 141 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/tukaani/xz/1.9/xz-1.9.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/tukaani/xz/1.9/xz-1.9.pom (2.0 kB at 27 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.26/plexus-interpolation-1.26.pom&#xA;Progress (1): 2.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.26/plexus-interpolation-1.26.pom (2.7 kB at 32 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.4.2/plexus-utils-3.4.2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 8.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.4.2/plexus-utils-3.4.2.pom (8.2 kB at 113 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/8/plexus-8.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 25 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/8/plexus-8.pom (25 kB at 339 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/file-management/3.1.0/file-management-3.1.0.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.11.0/commons-io-2.11.0.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-archiver/3.6.0/maven-archiver-3.6.0.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-io/3.4.0/plexus-io-3.4.0.jar&#xA;Progress (1): 4.1/41 kB&#xD;Progress (1): 7.7/41 kB&#xD;Progress (1): 12/41 kB &#xD;Progress (1): 16/41 kB&#xD;Progress (1): 20/41 kB&#xD;Progress (1): 24/41 kB&#xD;Progress (1): 28/41 kB&#xD;Progress (1): 32/41 kB&#xD;Progress (1): 36/41 kB&#xD;Progress (1): 40/41 kB&#xD;Progress (1): 41 kB   &#xD;Progress (2): 41 kB | 4.1/26 kB&#xD;Progress (2): 41 kB | 7.7/26 kB&#xD;Progress (2): 41 kB | 12/26 kB &#xD;Progress (2): 41 kB | 16/26 kB&#xD;Progress (2): 41 kB | 20/26 kB&#xD;Progress (2): 41 kB | 24/26 kB&#xD;Progress (2): 41 kB | 26 kB   &#xD;Progress (3): 41 kB | 26 kB | 4.1/36 kB&#xD;Progress (3): 41 kB | 26 kB | 7.7/36 kB&#xD;Progress (3): 41 kB | 26 kB | 12/36 kB &#xD;Progress (3): 41 kB | 26 kB | 16/36 kB&#xD;Progress (3): 41 kB | 26 kB | 20/36 kB&#xD;Progress (3): 41 kB | 26 kB | 24/36 kB&#xD;Progress (3): 41 kB | 26 kB | 28/36 kB&#xD;Progress (3): 41 kB | 26 kB | 32/36 kB&#xD;Progress (3): 41 kB | 26 kB | 36 kB   &#xD;Progress (4): 41 kB | 26 kB | 36 kB | 4.1/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 7.7/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 12/79 kB &#xD;Progress (4): 41 kB | 26 kB | 36 kB | 16/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 20/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 24/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 28/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 32/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 36/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 40/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 45/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 49/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 53/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 57/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 61/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 65/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 69/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 73/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 77/79 kB&#xD;Progress (4): 41 kB | 26 kB | 36 kB | 79 kB   &#xD;                                           &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/file-management/3.1.0/file-management-3.1.0.jar (36 kB at 727 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/javax/inject/javax.inject/1/javax.inject-1.jar&#xA;Progress (4): 41 kB | 26 kB | 79 kB | 4.1/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 7.7/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 12/327 kB &#xD;Progress (4): 41 kB | 26 kB | 79 kB | 16/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 20/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 24/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 28/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 32/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 36/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 40/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 45/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 49/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 53/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 57/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 61/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 65/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 69/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 73/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 77/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 81/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 86/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 90/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 94/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 98/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 102/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 106/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 110/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 114/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 118/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 122/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 126/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 131/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 135/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 139/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 143/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 147/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 151/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 155/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 159/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 163/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 167/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 172/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 176/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 180/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 184/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 188/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 192/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 196/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 200/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 204/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 208/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 213/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 217/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 221/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 225/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 229/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 233/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 237/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 241/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 245/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 249/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 253/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 258/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 262/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 266/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 270/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 274/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 278/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 282/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 286/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 290/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 294/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 299/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 303/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 307/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 311/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 314/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 318/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 322/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 326/327 kB&#xD;Progress (4): 41 kB | 26 kB | 79 kB | 327 kB    &#xD;                                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.jar (41 kB at 685 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-archiver/4.4.0/plexus-archiver-4.4.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-archiver/3.6.0/maven-archiver-3.6.0.jar (26 kB at 416 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-compress/1.21/commons-compress-1.21.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-io/3.4.0/plexus-io-3.4.0.jar (79 kB at 1.2 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/iq80/snappy/snappy/0.4/snappy-0.4.jar&#xA;Progress (2): 327 kB | 2.5 kB&#xD;                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.11.0/commons-io-2.11.0.jar (327 kB at 3.9 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/tukaani/xz/1.9/xz-1.9.jar&#xA;Progress (2): 2.5 kB | 0/1.0 MB&#xD;Progress (2): 2.5 kB | 0/1.0 MB&#xD;Progress (2): 2.5 kB | 0/1.0 MB&#xD;Progress (2): 2.5 kB | 0/1.0 MB&#xD;Progress (2): 2.5 kB | 0/1.0 MB&#xD;Progress (2): 2.5 kB | 0/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.1/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;Progress (2): 2.5 kB | 0.2/1.0 MB&#xD;                                 &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/javax/inject/javax.inject/1/javax.inject-1.jar (2.5 kB at 27 kB/s)&#xA;Progress (1): 0.2/1.0 MB&#xD;                        &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.26/plexus-interpolation-1.26.jar&#xA;Progress (1): 0.3/1.0 MB&#xD;Progress (1): 0.3/1.0 MB&#xD;Progress (1): 0.3/1.0 MB&#xD;Progress (1): 0.3/1.0 MB&#xD;Progress (1): 0.3/1.0 MB&#xD;Progress (2): 0.3/1.0 MB | 4.1/211 kB&#xD;Progress (2): 0.3/1.0 MB | 4.1/211 kB&#xD;Progress (2): 0.3/1.0 MB | 7.7/211 kB&#xD;Progress (2): 0.3/1.0 MB | 7.7/211 kB&#xD;Progress (2): 0.3/1.0 MB | 12/211 kB &#xD;Progress (2): 0.3/1.0 MB | 12/211 kB&#xD;Progress (2): 0.3/1.0 MB | 16/211 kB&#xD;Progress (2): 0.3/1.0 MB | 16/211 kB&#xD;Progress (2): 0.3/1.0 MB | 20/211 kB&#xD;Progress (2): 0.3/1.0 MB | 20/211 kB&#xD;Progress (2): 0.3/1.0 MB | 24/211 kB&#xD;Progress (2): 0.3/1.0 MB | 24/211 kB&#xD;Progress (2): 0.3/1.0 MB | 28/211 kB&#xD;Progress (2): 0.3/1.0 MB | 28/211 kB&#xD;Progress (2): 0.3/1.0 MB | 32/211 kB&#xD;Progress (2): 0.4/1.0 MB | 32/211 kB&#xD;Progress (2): 0.4/1.0 MB | 36/211 kB&#xD;Progress (2): 0.4/1.0 MB | 36/211 kB&#xD;Progress (2): 0.4/1.0 MB | 40/211 kB&#xD;Progress (2): 0.4/1.0 MB | 40/211 kB&#xD;Progress (2): 0.4/1.0 MB | 40/211 kB&#xD;Progress (2): 0.4/1.0 MB | 45/211 kB&#xD;Progress (2): 0.4/1.0 MB | 45/211 kB&#xD;Progress (2): 0.4/1.0 MB | 49/211 kB&#xD;Progress (2): 0.4/1.0 MB | 49/211 kB&#xD;Progress (2): 0.4/1.0 MB | 53/211 kB&#xD;Progress (2): 0.4/1.0 MB | 53/211 kB&#xD;Progress (2): 0.4/1.0 MB | 57/211 kB&#xD;Progress (2): 0.4/1.0 MB | 57/211 kB&#xD;Progress (2): 0.4/1.0 MB | 57/211 kB&#xD;Progress (2): 0.4/1.0 MB | 57/211 kB&#xD;Progress (2): 0.4/1.0 MB | 57/211 kB&#xD;Progress (2): 0.4/1.0 MB | 57/211 kB&#xD;Progress (2): 0.5/1.0 MB | 57/211 kB&#xD;Progress (2): 0.5/1.0 MB | 57/211 kB&#xD;Progress (2): 0.5/1.0 MB | 57/211 kB&#xD;Progress (2): 0.5/1.0 MB | 57/211 kB&#xD;Progress (2): 0.5/1.0 MB | 57/211 kB&#xD;Progress (2): 0.5/1.0 MB | 57/211 kB&#xD;Progress (2): 0.5/1.0 MB | 57/211 kB&#xD;Progress (2): 0.5/1.0 MB | 61/211 kB&#xD;Progress (2): 0.5/1.0 MB | 61/211 kB&#xD;Progress (2): 0.5/1.0 MB | 65/211 kB&#xD;Progress (2): 0.5/1.0 MB | 69/211 kB&#xD;Progress (2): 0.5/1.0 MB | 69/211 kB&#xD;Progress (2): 0.5/1.0 MB | 73/211 kB&#xD;Progress (2): 0.5/1.0 MB | 73/211 kB&#xD;Progress (2): 0.5/1.0 MB | 77/211 kB&#xD;Progress (2): 0.5/1.0 MB | 77/211 kB&#xD;Progress (2): 0.5/1.0 MB | 81/211 kB&#xD;Progress (2): 0.5/1.0 MB | 81/211 kB&#xD;Progress (2): 0.5/1.0 MB | 86/211 kB&#xD;Progress (2): 0.5/1.0 MB | 86/211 kB&#xD;Progress (2): 0.6/1.0 MB | 86/211 kB&#xD;Progress (2): 0.6/1.0 MB | 90/211 kB&#xD;Progress (2): 0.6/1.0 MB | 90/211 kB&#xD;Progress (2): 0.6/1.0 MB | 94/211 kB&#xD;Progress (2): 0.6/1.0 MB | 94/211 kB&#xD;Progress (2): 0.6/1.0 MB | 98/211 kB&#xD;Progress (2): 0.6/1.0 MB | 98/211 kB&#xD;Progress (2): 0.6/1.0 MB | 102/211 kB&#xD;Progress (2): 0.6/1.0 MB | 106/211 kB&#xD;Progress (2): 0.6/1.0 MB | 106/211 kB&#xD;Progress (2): 0.6/1.0 MB | 110/211 kB&#xD;Progress (2): 0.6/1.0 MB | 110/211 kB&#xD;Progress (2): 0.6/1.0 MB | 114/211 kB&#xD;Progress (2): 0.6/1.0 MB | 118/211 kB&#xD;Progress (2): 0.6/1.0 MB | 118/211 kB&#xD;Progress (2): 0.6/1.0 MB | 122/211 kB&#xD;Progress (2): 0.6/1.0 MB | 122/211 kB&#xD;Progress (2): 0.6/1.0 MB | 126/211 kB&#xD;Progress (2): 0.6/1.0 MB | 131/211 kB&#xD;Progress (2): 0.6/1.0 MB | 131/211 kB&#xD;Progress (2): 0.6/1.0 MB | 135/211 kB&#xD;Progress (2): 0.6/1.0 MB | 135/211 kB&#xD;Progress (2): 0.6/1.0 MB | 139/211 kB&#xD;Progress (2): 0.6/1.0 MB | 139/211 kB&#xD;Progress (2): 0.6/1.0 MB | 143/211 kB&#xD;Progress (2): 0.6/1.0 MB | 143/211 kB&#xD;Progress (2): 0.6/1.0 MB | 147/211 kB&#xD;Progress (2): 0.6/1.0 MB | 151/211 kB&#xD;Progress (2): 0.7/1.0 MB | 151/211 kB&#xD;Progress (2): 0.7/1.0 MB | 155/211 kB&#xD;Progress (2): 0.7/1.0 MB | 155/211 kB&#xD;Progress (2): 0.7/1.0 MB | 159/211 kB&#xD;Progress (2): 0.7/1.0 MB | 159/211 kB&#xD;Progress (2): 0.7/1.0 MB | 163/211 kB&#xD;Progress (2): 0.7/1.0 MB | 163/211 kB&#xD;Progress (2): 0.7/1.0 MB | 167/211 kB&#xD;Progress (2): 0.7/1.0 MB | 172/211 kB&#xD;Progress (2): 0.7/1.0 MB | 172/211 kB&#xD;Progress (2): 0.7/1.0 MB | 172/211 kB&#xD;Progress (2): 0.7/1.0 MB | 176/211 kB&#xD;Progress (2): 0.7/1.0 MB | 176/211 kB&#xD;Progress (2): 0.7/1.0 MB | 180/211 kB&#xD;Progress (2): 0.7/1.0 MB | 180/211 kB&#xD;Progress (2): 0.7/1.0 MB | 184/211 kB&#xD;Progress (2): 0.7/1.0 MB | 184/211 kB&#xD;Progress (2): 0.7/1.0 MB | 188/211 kB&#xD;Progress (2): 0.7/1.0 MB | 188/211 kB&#xD;Progress (2): 0.7/1.0 MB | 192/211 kB&#xD;Progress (2): 0.7/1.0 MB | 192/211 kB&#xD;Progress (2): 0.7/1.0 MB | 196/211 kB&#xD;Progress (2): 0.7/1.0 MB | 196/211 kB&#xD;Progress (2): 0.7/1.0 MB | 200/211 kB&#xD;Progress (2): 0.7/1.0 MB | 204/211 kB&#xD;Progress (2): 0.7/1.0 MB | 204/211 kB&#xD;Progress (2): 0.7/1.0 MB | 208/211 kB&#xD;Progress (2): 0.8/1.0 MB | 208/211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB    &#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.8/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 0.9/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0/1.0 MB | 211 kB&#xD;Progress (2): 1.0 MB | 211 kB    &#xD;Progress (3): 1.0 MB | 211 kB | 4.1/58 kB&#xD;Progress (3): 1.0 MB | 211 kB | 8.2/58 kB&#xD;Progress (3): 1.0 MB | 211 kB | 12/58 kB &#xD;Progress (3): 1.0 MB | 211 kB | 16/58 kB&#xD;Progress (4): 1.0 MB | 211 kB | 16/58 kB | 4.1/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 20/58 kB | 4.1/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 25/58 kB | 4.1/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 25/58 kB | 7.7/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 29/58 kB | 7.7/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 29/58 kB | 12/85 kB &#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 12/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 16/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 20/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 24/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 28/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 32/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 36/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 40/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 45/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 49/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 53/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 57/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 61/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 65/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 69/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 73/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 77/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 81/85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 33/58 kB | 85 kB   &#xD;Progress (4): 1.0 MB | 211 kB | 37/58 kB | 85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 41/58 kB | 85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 45/58 kB | 85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 49/58 kB | 85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 53/58 kB | 85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 57/58 kB | 85 kB&#xD;Progress (4): 1.0 MB | 211 kB | 58 kB | 85 kB   &#xD;                                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-compress/1.21/commons-compress-1.21.jar (1.0 MB at 8.4 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.4.2/plexus-utils-3.4.2.jar&#xA;Progress (4): 211 kB | 58 kB | 85 kB | 4.1/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 7.7/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 12/116 kB &#xD;Progress (4): 211 kB | 58 kB | 85 kB | 16/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 20/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 24/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 28/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 32/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 36/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 40/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 45/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 49/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 53/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 57/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 61/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 65/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 69/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 73/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 77/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 81/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 86/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 90/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 94/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 98/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 102/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 106/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 110/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 114/116 kB&#xD;Progress (4): 211 kB | 58 kB | 85 kB | 116 kB    &#xD;                                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-archiver/4.4.0/plexus-archiver-4.4.0.jar (211 kB at 1.6 MB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.26/plexus-interpolation-1.26.jar (85 kB at 593 kB/s)&#xA;Progress (3): 58 kB | 116 kB | 4.1/267 kB&#xD;Progress (3): 58 kB | 116 kB | 8.2/267 kB&#xD;Progress (3): 58 kB | 116 kB | 12/267 kB &#xD;Progress (3): 58 kB | 116 kB | 16/267 kB&#xD;Progress (3): 58 kB | 116 kB | 20/267 kB&#xD;Progress (3): 58 kB | 116 kB | 25/267 kB&#xD;Progress (3): 58 kB | 116 kB | 29/267 kB&#xD;Progress (3): 58 kB | 116 kB | 33/267 kB&#xD;Progress (3): 58 kB | 116 kB | 37/267 kB&#xD;Progress (3): 58 kB | 116 kB | 41/267 kB&#xD;Progress (3): 58 kB | 116 kB | 45/267 kB&#xD;Progress (3): 58 kB | 116 kB | 49/267 kB&#xD;Progress (3): 58 kB | 116 kB | 53/267 kB&#xD;Progress (3): 58 kB | 116 kB | 57/267 kB&#xD;Progress (3): 58 kB | 116 kB | 61/267 kB&#xD;Progress (3): 58 kB | 116 kB | 66/267 kB&#xD;Progress (3): 58 kB | 116 kB | 70/267 kB&#xD;Progress (3): 58 kB | 116 kB | 74/267 kB&#xD;Progress (3): 58 kB | 116 kB | 78/267 kB&#xD;Progress (3): 58 kB | 116 kB | 82/267 kB&#xD;Progress (3): 58 kB | 116 kB | 86/267 kB&#xD;Progress (3): 58 kB | 116 kB | 90/267 kB&#xD;Progress (3): 58 kB | 116 kB | 94/267 kB&#xD;Progress (3): 58 kB | 116 kB | 98/267 kB&#xD;Progress (3): 58 kB | 116 kB | 102/267 kB&#xD;Progress (3): 58 kB | 116 kB | 106/267 kB&#xD;Progress (3): 58 kB | 116 kB | 111/267 kB&#xD;Progress (3): 58 kB | 116 kB | 115/267 kB&#xD;Progress (3): 58 kB | 116 kB | 119/267 kB&#xD;Progress (3): 58 kB | 116 kB | 123/267 kB&#xD;Progress (3): 58 kB | 116 kB | 127/267 kB&#xD;Progress (3): 58 kB | 116 kB | 131/267 kB&#xD;Progress (3): 58 kB | 116 kB | 135/267 kB&#xD;Progress (3): 58 kB | 116 kB | 139/267 kB&#xD;Progress (3): 58 kB | 116 kB | 143/267 kB&#xD;Progress (3): 58 kB | 116 kB | 147/267 kB&#xD;Progress (3): 58 kB | 116 kB | 152/267 kB&#xD;Progress (3): 58 kB | 116 kB | 156/267 kB&#xD;Progress (3): 58 kB | 116 kB | 160/267 kB&#xD;Progress (3): 58 kB | 116 kB | 164/267 kB&#xD;Progress (3): 58 kB | 116 kB | 168/267 kB&#xD;Progress (3): 58 kB | 116 kB | 172/267 kB&#xD;Progress (3): 58 kB | 116 kB | 176/267 kB&#xD;Progress (3): 58 kB | 116 kB | 180/267 kB&#xD;Progress (3): 58 kB | 116 kB | 184/267 kB&#xD;Progress (3): 58 kB | 116 kB | 188/267 kB&#xD;Progress (3): 58 kB | 116 kB | 193/267 kB&#xD;Progress (3): 58 kB | 116 kB | 197/267 kB&#xD;Progress (3): 58 kB | 116 kB | 201/267 kB&#xD;Progress (3): 58 kB | 116 kB | 205/267 kB&#xD;Progress (3): 58 kB | 116 kB | 209/267 kB&#xD;Progress (3): 58 kB | 116 kB | 213/267 kB&#xD;Progress (3): 58 kB | 116 kB | 217/267 kB&#xD;Progress (3): 58 kB | 116 kB | 221/267 kB&#xD;Progress (3): 58 kB | 116 kB | 225/267 kB&#xD;Progress (3): 58 kB | 116 kB | 229/267 kB&#xD;Progress (3): 58 kB | 116 kB | 233/267 kB&#xD;Progress (3): 58 kB | 116 kB | 238/267 kB&#xD;Progress (3): 58 kB | 116 kB | 242/267 kB&#xD;Progress (3): 58 kB | 116 kB | 246/267 kB&#xD;Progress (3): 58 kB | 116 kB | 250/267 kB&#xD;Progress (3): 58 kB | 116 kB | 254/267 kB&#xD;Progress (3): 58 kB | 116 kB | 258/267 kB&#xD;Progress (3): 58 kB | 116 kB | 262/267 kB&#xD;Progress (3): 58 kB | 116 kB | 266/267 kB&#xD;Progress (3): 58 kB | 116 kB | 267 kB    &#xD;                                     &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/iq80/snappy/snappy/0.4/snappy-0.4.jar (58 kB at 379 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/tukaani/xz/1.9/xz-1.9.jar (116 kB at 691 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.4.2/plexus-utils-3.4.2.jar (267 kB at 1.5 MB/s)&#xA;[INFO] Building jar: /work/target/hacbs-test.jar&#xA;[INFO] &#xA;[INFO] --- maven-shade-plugin:3.2.4:shade (default) @ simple-java-project ---&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/3.0/maven-plugin-api-3.0.pom&#xA;Progress (1): 2.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/3.0/maven-plugin-api-3.0.pom (2.3 kB at 47 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven/3.0/maven-3.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 22 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven/3.0/maven-3.0.pom (22 kB at 405 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/15/maven-parent-15.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 24 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/15/maven-parent-15.pom (24 kB at 429 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/3.0/maven-model-3.0.pom&#xA;Progress (1): 3.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/3.0/maven-model-3.0.pom (3.9 kB at 93 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/2.0.4/plexus-utils-2.0.4.pom&#xA;Progress (1): 3.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/2.0.4/plexus-utils-2.0.4.pom (3.3 kB at 69 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/3.0/maven-artifact-3.0.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/3.0/maven-artifact-3.0.pom (1.9 kB at 43 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject-plexus/1.4.2/sisu-inject-plexus-1.4.2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject-plexus/1.4.2/sisu-inject-plexus-1.4.2.pom (5.4 kB at 91 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/inject/guice-plexus/1.4.2/guice-plexus-1.4.2.pom&#xA;Progress (1): 3.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/inject/guice-plexus/1.4.2/guice-plexus-1.4.2.pom (3.1 kB at 56 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/inject/guice-bean/1.4.2/guice-bean-1.4.2.pom&#xA;Progress (1): 2.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/inject/guice-bean/1.4.2/guice-bean-1.4.2.pom (2.6 kB at 47 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject/1.4.2/sisu-inject-1.4.2.pom&#xA;Progress (1): 1.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject/1.4.2/sisu-inject-1.4.2.pom (1.2 kB at 23 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-parent/1.4.2/sisu-parent-1.4.2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 7.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-parent/1.4.2/sisu-parent-1.4.2.pom (7.8 kB at 169 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/6/forge-parent-6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 11 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/forge/forge-parent/6/forge-parent-6.pom (11 kB at 182 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-component-annotations/2.0.0/plexus-component-annotations-2.0.0.pom&#xA;Progress (1): 750 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-component-annotations/2.0.0/plexus-component-annotations-2.0.0.pom (750 B at 15 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-containers/2.0.0/plexus-containers-2.0.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-containers/2.0.0/plexus-containers-2.0.0.pom (4.8 kB at 98 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-classworlds/2.2.3/plexus-classworlds-2.2.3.pom&#xA;Progress (1): 4.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-classworlds/2.2.3/plexus-classworlds-2.2.3.pom (4.0 kB at 64 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject-bean/1.4.2/sisu-inject-bean-1.4.2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject-bean/1.4.2/sisu-inject-bean-1.4.2.pom (5.5 kB at 121 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-guice/2.1.7/sisu-guice-2.1.7.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 11 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-guice/2.1.7/sisu-guice-2.1.7.pom (11 kB at 270 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/3.0/maven-core-3.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/3.0/maven-core-3.0.pom (6.6 kB at 138 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/3.0/maven-settings-3.0.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/3.0/maven-settings-3.0.pom (1.9 kB at 50 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings-builder/3.0/maven-settings-builder-3.0.pom&#xA;Progress (1): 2.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings-builder/3.0/maven-settings-builder-3.0.pom (2.2 kB at 53 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.14/plexus-interpolation-1.14.pom&#xA;Progress (1): 910 B&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.14/plexus-interpolation-1.14.pom (910 B at 21 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-components/1.1.18/plexus-components-1.1.18.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-components/1.1.18/plexus-components-1.1.18.pom (5.4 kB at 122 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/3.0/maven-repository-metadata-3.0.pom&#xA;Progress (1): 1.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/3.0/maven-repository-metadata-3.0.pom (1.9 kB at 58 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model-builder/3.0/maven-model-builder-3.0.pom&#xA;Progress (1): 2.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model-builder/3.0/maven-model-builder-3.0.pom (2.2 kB at 56 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-aether-provider/3.0/maven-aether-provider-3.0.pom&#xA;Progress (1): 2.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-aether-provider/3.0/maven-aether-provider-3.0.pom (2.5 kB at 50 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-api/1.7/aether-api-1.7.pom&#xA;Progress (1): 1.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-api/1.7/aether-api-1.7.pom (1.7 kB at 29 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-parent/1.7/aether-parent-1.7.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 7.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-parent/1.7/aether-parent-1.7.pom (7.7 kB at 80 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-util/1.7/aether-util-1.7.pom&#xA;Progress (1): 2.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-util/1.7/aether-util-1.7.pom (2.1 kB at 32 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-impl/1.7/aether-impl-1.7.pom&#xA;Progress (1): 3.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-impl/1.7/aether-impl-1.7.pom (3.7 kB at 70 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-spi/1.7/aether-spi-1.7.pom&#xA;Progress (1): 1.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-spi/1.7/aether-spi-1.7.pom (1.7 kB at 35 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-artifact-transfer/0.12.0/maven-artifact-transfer-0.12.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 11 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-artifact-transfer/0.12.0/maven-artifact-transfer-0.12.0.pom (11 kB at 250 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/33/maven-shared-components-33.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/33/maven-shared-components-33.pom (5.1 kB at 86 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/33/maven-parent-33.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 44 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/33/maven-parent-33.pom (44 kB at 981 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/21/apache-21.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 17 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/21/apache-21.pom (17 kB at 398 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-common-artifact-filters/3.0.1/maven-common-artifact-filters-3.0.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-common-artifact-filters/3.0.1/maven-common-artifact-filters-3.0.1.pom (4.8 kB at 151 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/30/maven-shared-components-30.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-components/30/maven-shared-components-30.pom (4.6 kB at 95 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/30/maven-parent-30.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 41 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/30/maven-parent-30.pom (41 kB at 1.1 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/18/apache-18.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/18/apache-18.pom (16 kB at 112 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-utils/3.1.0/maven-shared-utils-3.1.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-utils/3.1.0/maven-shared-utils-3.1.0.pom (5.0 kB at 98 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.5/commons-io-2.5.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 13 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.5/commons-io-2.5.pom (13 kB at 341 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-parent/39/commons-parent-39.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 45 kB&#xD;Progress (1): 49 kB&#xD;Progress (1): 53 kB&#xD;Progress (1): 57 kB&#xD;Progress (1): 61 kB&#xD;Progress (1): 62 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-parent/39/commons-parent-39.pom (62 kB at 1.3 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/16/apache-16.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 15 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/16/apache-16.pom (15 kB at 395 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.1.1/plexus-utils-3.1.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.1.1/plexus-utils-3.1.1.pom (5.1 kB at 52 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/4.0/plexus-4.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 22 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus/4.0/plexus-4.0.pom (22 kB at 398 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-codec/commons-codec/1.11/commons-codec-1.11.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 14 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/commons-codec/commons-codec/1.11/commons-codec-1.11.pom (14 kB at 317 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-parent/42/commons-parent-42.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 29 kB&#xD;Progress (1): 33 kB&#xD;Progress (1): 37 kB&#xD;Progress (1): 41 kB&#xD;Progress (1): 45 kB&#xD;Progress (1): 49 kB&#xD;Progress (1): 53 kB&#xD;Progress (1): 57 kB&#xD;Progress (1): 61 kB&#xD;Progress (1): 66 kB&#xD;Progress (1): 68 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-parent/42/commons-parent-42.pom (68 kB at 1.4 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.7.5/slf4j-api-1.7.5.pom&#xA;Progress (1): 2.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.7.5/slf4j-api-1.7.5.pom (2.7 kB at 57 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-parent/1.7.5/slf4j-parent-1.7.5.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-parent/1.7.5/slf4j-parent-1.7.5.pom (12 kB at 236 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm/8.0/asm-8.0.pom&#xA;Progress (1): 2.9 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm/8.0/asm-8.0.pom (2.9 kB at 63 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/ow2/1.5/ow2-1.5.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 11 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/ow2/1.5/ow2-1.5.pom (11 kB at 244 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-commons/8.0/asm-commons-8.0.pom&#xA;Progress (1): 3.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-commons/8.0/asm-commons-8.0.pom (3.7 kB at 80 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-tree/8.0/asm-tree-8.0.pom&#xA;Progress (1): 3.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-tree/8.0/asm-tree-8.0.pom (3.1 kB at 64 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-analysis/8.0/asm-analysis-8.0.pom&#xA;Progress (1): 3.2 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-analysis/8.0/asm-analysis-8.0.pom (3.2 kB at 62 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/jdom/jdom2/2.0.6/jdom2-2.0.6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/jdom/jdom2/2.0.6/jdom2-2.0.6.pom (4.6 kB at 100 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-dependency-tree/3.0.1/maven-dependency-tree-3.0.1.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 7.5 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-dependency-tree/3.0.1/maven-dependency-tree-3.0.1.pom (7.5 kB at 170 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/eclipse/aether/aether-util/0.9.0.M2/aether-util-0.9.0.M2.pom&#xA;Progress (1): 2.0 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/eclipse/aether/aether-util/0.9.0.M2/aether-util-0.9.0.M2.pom (2.0 kB at 47 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/eclipse/aether/aether/0.9.0.M2/aether-0.9.0.M2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 28 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/eclipse/aether/aether/0.9.0.M2/aether-0.9.0.M2.pom (28 kB at 715 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.6/commons-io-2.6.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 14 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.6/commons-io-2.6.pom (14 kB at 183 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/vafer/jdependency/2.4.0/jdependency-2.4.0.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 15 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/vafer/jdependency/2.4.0/jdependency-2.4.0.pom (15 kB at 284 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-util/8.0/asm-util-8.0.pom&#xA;Progress (1): 3.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-util/8.0/asm-util-8.0.pom (3.7 kB at 61 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/guava/guava/28.2-android/guava-28.2-android.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 11 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/guava/guava/28.2-android/guava-28.2-android.pom (11 kB at 195 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/guava/guava-parent/28.2-android/guava-parent-28.2-android.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 13 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/guava/guava-parent/28.2-android/guava-parent-28.2-android.pom (13 kB at 258 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/guava/failureaccess/1.0.1/failureaccess-1.0.1.pom&#xA;Progress (1): 2.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/guava/failureaccess/1.0.1/failureaccess-1.0.1.pom (2.4 kB at 31 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/guava/guava-parent/26.0-android/guava-parent-26.0-android.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 10 kB &#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/guava/guava-parent/26.0-android/guava-parent-26.0-android.pom (10 kB at 248 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/oss/oss-parent/9/oss-parent-9.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 6.6 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/oss/oss-parent/9/oss-parent-9.pom (6.6 kB at 156 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/guava/listenablefuture/9999.0-empty-to-avoid-conflict-with-guava/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.pom&#xA;Progress (1): 2.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/guava/listenablefuture/9999.0-empty-to-avoid-conflict-with-guava/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.pom (2.3 kB at 56 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.3 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.pom (4.3 kB at 81 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/oss/oss-parent/7/oss-parent-7.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 4.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/oss/oss-parent/7/oss-parent-7.pom (4.8 kB at 88 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/checkerframework/checker-compat-qual/2.5.5/checker-compat-qual-2.5.5.pom&#xA;Progress (1): 2.7 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/checkerframework/checker-compat-qual/2.5.5/checker-compat-qual-2.5.5.pom (2.7 kB at 37 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/errorprone/error_prone_annotations/2.3.4/error_prone_annotations-2.3.4.pom&#xA;Progress (1): 2.1 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/errorprone/error_prone_annotations/2.3.4/error_prone_annotations-2.3.4.pom (2.1 kB at 45 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/errorprone/error_prone_parent/2.3.4/error_prone_parent-2.3.4.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 5.4 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/errorprone/error_prone_parent/2.3.4/error_prone_parent-2.3.4.pom (5.4 kB at 111 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/j2objc/j2objc-annotations/1.3/j2objc-annotations-1.3.pom&#xA;Progress (1): 2.8 kB&#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/j2objc/j2objc-annotations/1.3/j2objc-annotations-1.3.pom (2.8 kB at 79 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-lang3/3.7/commons-lang3-3.7.pom&#xA;Progress (1): 4.1 kB&#xD;Progress (1): 8.2 kB&#xD;Progress (1): 12 kB &#xD;Progress (1): 16 kB&#xD;Progress (1): 20 kB&#xD;Progress (1): 25 kB&#xD;Progress (1): 28 kB&#xD;                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-lang3/3.7/commons-lang3-3.7.pom (28 kB at 574 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/3.0/maven-plugin-api-3.0.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject-plexus/1.4.2/sisu-inject-plexus-1.4.2.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject-bean/1.4.2/sisu-inject-bean-1.4.2.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-guice/2.1.7/sisu-guice-2.1.7-noaop.jar&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/3.0/maven-model-3.0.jar&#xA;Progress (1): 4.1/49 kB&#xD;Progress (1): 7.7/49 kB&#xD;Progress (1): 12/49 kB &#xD;Progress (1): 16/49 kB&#xD;Progress (1): 20/49 kB&#xD;Progress (1): 24/49 kB&#xD;Progress (1): 28/49 kB&#xD;Progress (1): 32/49 kB&#xD;Progress (1): 36/49 kB&#xD;Progress (1): 40/49 kB&#xD;Progress (1): 45/49 kB&#xD;Progress (1): 49/49 kB&#xD;Progress (1): 49 kB   &#xD;Progress (2): 49 kB | 4.1/472 kB&#xD;Progress (2): 49 kB | 7.7/472 kB&#xD;Progress (2): 49 kB | 12/472 kB &#xD;Progress (2): 49 kB | 16/472 kB&#xD;Progress (2): 49 kB | 20/472 kB&#xD;Progress (2): 49 kB | 24/472 kB&#xD;Progress (2): 49 kB | 28/472 kB&#xD;Progress (2): 49 kB | 32/472 kB&#xD;Progress (2): 49 kB | 36/472 kB&#xD;Progress (2): 49 kB | 40/472 kB&#xD;Progress (2): 49 kB | 45/472 kB&#xD;Progress (2): 49 kB | 49/472 kB&#xD;Progress (2): 49 kB | 53/472 kB&#xD;Progress (2): 49 kB | 57/472 kB&#xD;Progress (2): 49 kB | 61/472 kB&#xD;Progress (2): 49 kB | 65/472 kB&#xD;Progress (2): 49 kB | 69/472 kB&#xD;Progress (2): 49 kB | 73/472 kB&#xD;Progress (2): 49 kB | 77/472 kB&#xD;Progress (2): 49 kB | 81/472 kB&#xD;Progress (2): 49 kB | 86/472 kB&#xD;Progress (2): 49 kB | 90/472 kB&#xD;Progress (2): 49 kB | 94/472 kB&#xD;Progress (2): 49 kB | 98/472 kB&#xD;Progress (3): 49 kB | 98/472 kB | 4.1/153 kB&#xD;Progress (3): 49 kB | 98/472 kB | 7.7/153 kB&#xD;Progress (3): 49 kB | 98/472 kB | 12/153 kB &#xD;Progress (3): 49 kB | 98/472 kB | 16/153 kB&#xD;Progress (3): 49 kB | 98/472 kB | 20/153 kB&#xD;Progress (3): 49 kB | 98/472 kB | 24/153 kB&#xD;Progress (3): 49 kB | 102/472 kB | 24/153 kB&#xD;Progress (3): 49 kB | 102/472 kB | 28/153 kB&#xD;Progress (3): 49 kB | 106/472 kB | 28/153 kB&#xD;Progress (3): 49 kB | 110/472 kB | 28/153 kB&#xD;Progress (3): 49 kB | 110/472 kB | 32/153 kB&#xD;Progress (3): 49 kB | 114/472 kB | 32/153 kB&#xD;Progress (3): 49 kB | 114/472 kB | 36/153 kB&#xD;Progress (3): 49 kB | 114/472 kB | 40/153 kB&#xD;Progress (3): 49 kB | 118/472 kB | 40/153 kB&#xD;Progress (3): 49 kB | 118/472 kB | 44/153 kB&#xD;Progress (3): 49 kB | 122/472 kB | 44/153 kB&#xD;Progress (3): 49 kB | 122/472 kB | 48/153 kB&#xD;Progress (3): 49 kB | 126/472 kB | 48/153 kB&#xD;Progress (3): 49 kB | 126/472 kB | 53/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 53/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 57/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 61/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 65/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 69/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 73/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 77/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 81/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 85/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 89/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 93/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 98/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 102/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 106/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 110/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 114/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 118/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 122/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 126/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 130/153 kB&#xD;Progress (3): 49 kB | 131/472 kB | 134/153 kB&#xD;Progress (3): 49 kB | 135/472 kB | 134/153 kB&#xD;Progress (3): 49 kB | 135/472 kB | 139/153 kB&#xD;Progress (3): 49 kB | 135/472 kB | 143/153 kB&#xD;Progress (3): 49 kB | 139/472 kB | 143/153 kB&#xD;Progress (3): 49 kB | 139/472 kB | 147/153 kB&#xD;Progress (3): 49 kB | 143/472 kB | 147/153 kB&#xD;Progress (3): 49 kB | 143/472 kB | 151/153 kB&#xD;Progress (3): 49 kB | 147/472 kB | 151/153 kB&#xD;Progress (3): 49 kB | 147/472 kB | 153 kB    &#xD;Progress (3): 49 kB | 151/472 kB | 153 kB&#xD;Progress (3): 49 kB | 155/472 kB | 153 kB&#xD;Progress (3): 49 kB | 159/472 kB | 153 kB&#xD;Progress (3): 49 kB | 163/472 kB | 153 kB&#xD;Progress (3): 49 kB | 167/472 kB | 153 kB&#xD;Progress (3): 49 kB | 172/472 kB | 153 kB&#xD;Progress (3): 49 kB | 176/472 kB | 153 kB&#xD;Progress (3): 49 kB | 180/472 kB | 153 kB&#xD;Progress (3): 49 kB | 184/472 kB | 153 kB&#xD;Progress (3): 49 kB | 188/472 kB | 153 kB&#xD;Progress (3): 49 kB | 192/472 kB | 153 kB&#xD;Progress (3): 49 kB | 196/472 kB | 153 kB&#xD;Progress (3): 49 kB | 200/472 kB | 153 kB&#xD;Progress (3): 49 kB | 204/472 kB | 153 kB&#xD;Progress (3): 49 kB | 208/472 kB | 153 kB&#xD;Progress (3): 49 kB | 212/472 kB | 153 kB&#xD;Progress (3): 49 kB | 217/472 kB | 153 kB&#xD;Progress (3): 49 kB | 221/472 kB | 153 kB&#xD;Progress (3): 49 kB | 224/472 kB | 153 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 4.1/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 7.7/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 12/165 kB &#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 16/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 20/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 24/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 28/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 32/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 36/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 40/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 45/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 49/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 53/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 57/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 61/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 65/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 69/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 73/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 77/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 81/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 86/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 90/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 94/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 98/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 102/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 106/165 kB&#xD;Progress (4): 49 kB | 224/472 kB | 153 kB | 110/165 kB&#xD;Progress (4): 49 kB | 228/472 kB | 153 kB | 110/165 kB&#xD;Progress (4): 49 kB | 228/472 kB | 153 kB | 114/165 kB&#xD;Progress (4): 49 kB | 233/472 kB | 153 kB | 114/165 kB&#xD;Progress (4): 49 kB | 233/472 kB | 153 kB | 118/165 kB&#xD;Progress (4): 49 kB | 237/472 kB | 153 kB | 118/165 kB&#xD;Progress (4): 49 kB | 237/472 kB | 153 kB | 122/165 kB&#xD;Progress (4): 49 kB | 241/472 kB | 153 kB | 122/165 kB&#xD;Progress (4): 49 kB | 241/472 kB | 153 kB | 126/165 kB&#xD;Progress (4): 49 kB | 245/472 kB | 153 kB | 126/165 kB&#xD;Progress (4): 49 kB | 245/472 kB | 153 kB | 131/165 kB&#xD;Progress (4): 49 kB | 249/472 kB | 153 kB | 131/165 kB&#xD;Progress (4): 49 kB | 249/472 kB | 153 kB | 135/165 kB&#xD;Progress (4): 49 kB | 253/472 kB | 153 kB | 135/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 135/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 139/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 143/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 147/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 151/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 155/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 159/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 163/165 kB&#xD;Progress (4): 49 kB | 257/472 kB | 153 kB | 165 kB    &#xD;Progress (4): 49 kB | 261/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 265/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 269/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 273/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 278/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 282/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 286/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 290/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 294/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 298/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 302/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 306/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 310/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 314/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 319/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 323/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 327/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 331/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 335/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 339/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 343/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 347/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 351/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 355/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 359/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 364/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 368/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 372/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 376/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 380/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 384/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 388/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 392/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 396/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 400/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 405/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 409/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 413/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 417/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 421/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 425/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 429/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 433/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 437/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 441/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 446/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 450/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 454/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 458/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 462/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 466/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 470/472 kB | 153 kB | 165 kB&#xD;Progress (4): 49 kB | 472 kB | 153 kB | 165 kB    &#xD;                                              &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-plugin-api/3.0/maven-plugin-api-3.0.jar (49 kB at 978 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/3.0/maven-core-3.0.jar&#xA;Progress (4): 472 kB | 153 kB | 165 kB | 4.1/202 kB&#xD;Progress (4): 472 kB | 153 kB | 165 kB | 7.7/202 kB&#xD;Progress (4): 472 kB | 153 kB | 165 kB | 12/202 kB &#xD;Progress (4): 472 kB | 153 kB | 165 kB | 16/202 kB&#xD;                                                  &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject-bean/1.4.2/sisu-inject-bean-1.4.2.jar (153 kB at 2.5 MB/s)&#xA;Progress (3): 472 kB | 165 kB | 20/202 kB&#xD;                                         &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/3.0/maven-settings-3.0.jar&#xA;Progress (3): 472 kB | 165 kB | 24/202 kB&#xD;Progress (3): 472 kB | 165 kB | 28/202 kB&#xD;Progress (3): 472 kB | 165 kB | 32/202 kB&#xD;Progress (3): 472 kB | 165 kB | 36/202 kB&#xD;Progress (3): 472 kB | 165 kB | 40/202 kB&#xD;Progress (3): 472 kB | 165 kB | 45/202 kB&#xD;Progress (3): 472 kB | 165 kB | 49/202 kB&#xD;Progress (3): 472 kB | 165 kB | 53/202 kB&#xD;Progress (3): 472 kB | 165 kB | 57/202 kB&#xD;Progress (3): 472 kB | 165 kB | 61/202 kB&#xD;Progress (3): 472 kB | 165 kB | 65/202 kB&#xD;Progress (3): 472 kB | 165 kB | 69/202 kB&#xD;Progress (3): 472 kB | 165 kB | 73/202 kB&#xD;Progress (3): 472 kB | 165 kB | 77/202 kB&#xD;Progress (3): 472 kB | 165 kB | 81/202 kB&#xD;Progress (3): 472 kB | 165 kB | 86/202 kB&#xD;Progress (3): 472 kB | 165 kB | 90/202 kB&#xD;Progress (3): 472 kB | 165 kB | 94/202 kB&#xD;Progress (3): 472 kB | 165 kB | 98/202 kB&#xD;Progress (3): 472 kB | 165 kB | 102/202 kB&#xD;Progress (3): 472 kB | 165 kB | 106/202 kB&#xD;Progress (3): 472 kB | 165 kB | 110/202 kB&#xD;Progress (3): 472 kB | 165 kB | 114/202 kB&#xD;Progress (3): 472 kB | 165 kB | 118/202 kB&#xD;Progress (3): 472 kB | 165 kB | 122/202 kB&#xD;Progress (3): 472 kB | 165 kB | 126/202 kB&#xD;Progress (3): 472 kB | 165 kB | 131/202 kB&#xD;Progress (3): 472 kB | 165 kB | 135/202 kB&#xD;Progress (3): 472 kB | 165 kB | 139/202 kB&#xD;Progress (3): 472 kB | 165 kB | 143/202 kB&#xD;Progress (3): 472 kB | 165 kB | 147/202 kB&#xD;Progress (3): 472 kB | 165 kB | 151/202 kB&#xD;Progress (3): 472 kB | 165 kB | 155/202 kB&#xD;Progress (3): 472 kB | 165 kB | 159/202 kB&#xD;Progress (3): 472 kB | 165 kB | 163/202 kB&#xD;Progress (3): 472 kB | 165 kB | 167/202 kB&#xD;Progress (3): 472 kB | 165 kB | 172/202 kB&#xD;Progress (3): 472 kB | 165 kB | 176/202 kB&#xD;Progress (3): 472 kB | 165 kB | 180/202 kB&#xD;Progress (3): 472 kB | 165 kB | 184/202 kB&#xD;Progress (3): 472 kB | 165 kB | 188/202 kB&#xD;Progress (3): 472 kB | 165 kB | 192/202 kB&#xD;Progress (3): 472 kB | 165 kB | 196/202 kB&#xD;Progress (3): 472 kB | 165 kB | 200/202 kB&#xD;Progress (3): 472 kB | 165 kB | 202 kB    &#xD;                                      &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model/3.0/maven-model-3.0.jar (165 kB at 2.5 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings-builder/3.0/maven-settings-builder-3.0.jar&#xA;Progress (3): 472 kB | 202 kB | 4.1/527 kB&#xD;Progress (3): 472 kB | 202 kB | 7.7/527 kB&#xD;Progress (3): 472 kB | 202 kB | 12/527 kB &#xD;Progress (3): 472 kB | 202 kB | 16/527 kB&#xD;Progress (3): 472 kB | 202 kB | 20/527 kB&#xD;Progress (3): 472 kB | 202 kB | 24/527 kB&#xD;Progress (3): 472 kB | 202 kB | 28/527 kB&#xD;Progress (3): 472 kB | 202 kB | 32/527 kB&#xD;Progress (3): 472 kB | 202 kB | 36/527 kB&#xD;Progress (3): 472 kB | 202 kB | 40/527 kB&#xD;Progress (3): 472 kB | 202 kB | 44/527 kB&#xD;Progress (3): 472 kB | 202 kB | 48/527 kB&#xD;Progress (3): 472 kB | 202 kB | 53/527 kB&#xD;Progress (3): 472 kB | 202 kB | 57/527 kB&#xD;Progress (3): 472 kB | 202 kB | 61/527 kB&#xD;Progress (3): 472 kB | 202 kB | 65/527 kB&#xD;Progress (3): 472 kB | 202 kB | 69/527 kB&#xD;Progress (3): 472 kB | 202 kB | 73/527 kB&#xD;Progress (3): 472 kB | 202 kB | 77/527 kB&#xD;Progress (3): 472 kB | 202 kB | 81/527 kB&#xD;Progress (3): 472 kB | 202 kB | 85/527 kB&#xD;Progress (3): 472 kB | 202 kB | 89/527 kB&#xD;Progress (3): 472 kB | 202 kB | 93/527 kB&#xD;Progress (3): 472 kB | 202 kB | 98/527 kB&#xD;Progress (3): 472 kB | 202 kB | 102/527 kB&#xD;Progress (3): 472 kB | 202 kB | 106/527 kB&#xD;Progress (3): 472 kB | 202 kB | 110/527 kB&#xD;Progress (3): 472 kB | 202 kB | 114/527 kB&#xD;Progress (3): 472 kB | 202 kB | 118/527 kB&#xD;Progress (3): 472 kB | 202 kB | 122/527 kB&#xD;Progress (3): 472 kB | 202 kB | 126/527 kB&#xD;Progress (3): 472 kB | 202 kB | 130/527 kB&#xD;Progress (3): 472 kB | 202 kB | 134/527 kB&#xD;Progress (3): 472 kB | 202 kB | 139/527 kB&#xD;Progress (3): 472 kB | 202 kB | 143/527 kB&#xD;Progress (3): 472 kB | 202 kB | 147/527 kB&#xD;Progress (3): 472 kB | 202 kB | 151/527 kB&#xD;Progress (3): 472 kB | 202 kB | 155/527 kB&#xD;Progress (3): 472 kB | 202 kB | 159/527 kB&#xD;Progress (3): 472 kB | 202 kB | 163/527 kB&#xD;Progress (3): 472 kB | 202 kB | 167/527 kB&#xD;Progress (3): 472 kB | 202 kB | 171/527 kB&#xD;Progress (3): 472 kB | 202 kB | 175/527 kB&#xD;Progress (3): 472 kB | 202 kB | 179/527 kB&#xD;Progress (3): 472 kB | 202 kB | 184/527 kB&#xD;Progress (3): 472 kB | 202 kB | 188/527 kB&#xD;Progress (3): 472 kB | 202 kB | 192/527 kB&#xD;Progress (3): 472 kB | 202 kB | 196/527 kB&#xD;Progress (3): 472 kB | 202 kB | 200/527 kB&#xD;Progress (3): 472 kB | 202 kB | 204/527 kB&#xD;Progress (3): 472 kB | 202 kB | 208/527 kB&#xD;Progress (3): 472 kB | 202 kB | 212/527 kB&#xD;Progress (3): 472 kB | 202 kB | 216/527 kB&#xD;Progress (3): 472 kB | 202 kB | 220/527 kB&#xD;Progress (3): 472 kB | 202 kB | 225/527 kB&#xD;Progress (3): 472 kB | 202 kB | 229/527 kB&#xD;Progress (3): 472 kB | 202 kB | 233/527 kB&#xD;Progress (3): 472 kB | 202 kB | 237/527 kB&#xD;Progress (3): 472 kB | 202 kB | 241/527 kB&#xD;Progress (3): 472 kB | 202 kB | 245/527 kB&#xD;Progress (3): 472 kB | 202 kB | 249/527 kB&#xD;Progress (3): 472 kB | 202 kB | 253/527 kB&#xD;Progress (3): 472 kB | 202 kB | 257/527 kB&#xD;Progress (3): 472 kB | 202 kB | 261/527 kB&#xD;Progress (3): 472 kB | 202 kB | 266/527 kB&#xD;Progress (3): 472 kB | 202 kB | 270/527 kB&#xD;Progress (3): 472 kB | 202 kB | 274/527 kB&#xD;Progress (3): 472 kB | 202 kB | 278/527 kB&#xD;Progress (3): 472 kB | 202 kB | 282/527 kB&#xD;Progress (3): 472 kB | 202 kB | 286/527 kB&#xD;Progress (3): 472 kB | 202 kB | 290/527 kB&#xD;Progress (3): 472 kB | 202 kB | 294/527 kB&#xD;Progress (3): 472 kB | 202 kB | 298/527 kB&#xD;Progress (3): 472 kB | 202 kB | 302/527 kB&#xD;Progress (3): 472 kB | 202 kB | 306/527 kB&#xD;Progress (3): 472 kB | 202 kB | 311/527 kB&#xD;Progress (3): 472 kB | 202 kB | 315/527 kB&#xD;Progress (3): 472 kB | 202 kB | 319/527 kB&#xD;Progress (3): 472 kB | 202 kB | 323/527 kB&#xD;Progress (3): 472 kB | 202 kB | 327/527 kB&#xD;Progress (3): 472 kB | 202 kB | 331/527 kB&#xD;Progress (3): 472 kB | 202 kB | 335/527 kB&#xD;Progress (3): 472 kB | 202 kB | 339/527 kB&#xD;Progress (3): 472 kB | 202 kB | 343/527 kB&#xD;Progress (3): 472 kB | 202 kB | 347/527 kB&#xD;Progress (3): 472 kB | 202 kB | 352/527 kB&#xD;Progress (3): 472 kB | 202 kB | 356/527 kB&#xD;Progress (3): 472 kB | 202 kB | 360/527 kB&#xD;Progress (3): 472 kB | 202 kB | 364/527 kB&#xD;Progress (3): 472 kB | 202 kB | 368/527 kB&#xD;Progress (3): 472 kB | 202 kB | 372/527 kB&#xD;Progress (3): 472 kB | 202 kB | 376/527 kB&#xD;Progress (3): 472 kB | 202 kB | 380/527 kB&#xD;Progress (3): 472 kB | 202 kB | 384/527 kB&#xD;Progress (3): 472 kB | 202 kB | 388/527 kB&#xD;Progress (3): 472 kB | 202 kB | 392/527 kB&#xD;Progress (3): 472 kB | 202 kB | 397/527 kB&#xD;Progress (3): 472 kB | 202 kB | 401/527 kB&#xD;Progress (3): 472 kB | 202 kB | 405/527 kB&#xD;Progress (3): 472 kB | 202 kB | 409/527 kB&#xD;                                          &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-guice/2.1.7/sisu-guice-2.1.7-noaop.jar (472 kB at 6.4 MB/s)&#xA;Progress (2): 202 kB | 413/527 kB&#xD;                                 &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/3.0/maven-repository-metadata-3.0.jar&#xA;Progress (2): 202 kB | 417/527 kB&#xD;Progress (2): 202 kB | 421/527 kB&#xD;Progress (2): 202 kB | 425/527 kB&#xD;Progress (2): 202 kB | 429/527 kB&#xD;Progress (2): 202 kB | 433/527 kB&#xD;Progress (2): 202 kB | 438/527 kB&#xD;Progress (2): 202 kB | 442/527 kB&#xD;Progress (2): 202 kB | 446/527 kB&#xD;Progress (2): 202 kB | 450/527 kB&#xD;Progress (2): 202 kB | 454/527 kB&#xD;Progress (2): 202 kB | 458/527 kB&#xD;Progress (2): 202 kB | 462/527 kB&#xD;Progress (2): 202 kB | 466/527 kB&#xD;Progress (2): 202 kB | 470/527 kB&#xD;Progress (2): 202 kB | 474/527 kB&#xD;Progress (2): 202 kB | 479/527 kB&#xD;Progress (2): 202 kB | 483/527 kB&#xD;Progress (2): 202 kB | 487/527 kB&#xD;Progress (2): 202 kB | 491/527 kB&#xD;Progress (2): 202 kB | 494/527 kB&#xD;Progress (2): 202 kB | 498/527 kB&#xD;Progress (2): 202 kB | 502/527 kB&#xD;Progress (2): 202 kB | 506/527 kB&#xD;Progress (2): 202 kB | 510/527 kB&#xD;Progress (2): 202 kB | 514/527 kB&#xD;Progress (2): 202 kB | 519/527 kB&#xD;Progress (2): 202 kB | 523/527 kB&#xD;Progress (2): 202 kB | 527/527 kB&#xD;Progress (2): 202 kB | 527 kB    &#xD;Progress (3): 202 kB | 527 kB | 4.1/47 kB&#xD;Progress (3): 202 kB | 527 kB | 8.2/47 kB&#xD;Progress (3): 202 kB | 527 kB | 12/47 kB &#xD;Progress (3): 202 kB | 527 kB | 16/47 kB&#xD;Progress (3): 202 kB | 527 kB | 20/47 kB&#xD;Progress (3): 202 kB | 527 kB | 25/47 kB&#xD;Progress (3): 202 kB | 527 kB | 29/47 kB&#xD;Progress (3): 202 kB | 527 kB | 33/47 kB&#xD;Progress (3): 202 kB | 527 kB | 37/47 kB&#xD;Progress (3): 202 kB | 527 kB | 41/47 kB&#xD;Progress (3): 202 kB | 527 kB | 45/47 kB&#xD;Progress (3): 202 kB | 527 kB | 47 kB   &#xD;                                     &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-core/3.0/maven-core-3.0.jar (527 kB at 5.5 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model-builder/3.0/maven-model-builder-3.0.jar&#xA;Progress (3): 202 kB | 47 kB | 4.1/38 kB&#xD;Progress (3): 202 kB | 47 kB | 7.7/38 kB&#xD;Progress (3): 202 kB | 47 kB | 12/38 kB &#xD;Progress (3): 202 kB | 47 kB | 16/38 kB&#xD;Progress (3): 202 kB | 47 kB | 20/38 kB&#xD;Progress (3): 202 kB | 47 kB | 22/38 kB&#xD;Progress (3): 202 kB | 47 kB | 26/38 kB&#xD;Progress (3): 202 kB | 47 kB | 30/38 kB&#xD;Progress (3): 202 kB | 47 kB | 34/38 kB&#xD;Progress (3): 202 kB | 47 kB | 38 kB   &#xD;Progress (4): 202 kB | 47 kB | 38 kB | 4.1/30 kB&#xD;Progress (4): 202 kB | 47 kB | 38 kB | 7.7/30 kB&#xD;Progress (4): 202 kB | 47 kB | 38 kB | 12/30 kB &#xD;Progress (4): 202 kB | 47 kB | 38 kB | 16/30 kB&#xD;Progress (4): 202 kB | 47 kB | 38 kB | 20/30 kB&#xD;Progress (4): 202 kB | 47 kB | 38 kB | 24/30 kB&#xD;Progress (4): 202 kB | 47 kB | 38 kB | 28/30 kB&#xD;Progress (4): 202 kB | 47 kB | 38 kB | 30 kB   &#xD;                                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings/3.0/maven-settings-3.0.jar (47 kB at 420 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-aether-provider/3.0/maven-aether-provider-3.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/sisu/sisu-inject-plexus/1.4.2/sisu-inject-plexus-1.4.2.jar (202 kB at 1.7 MB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-impl/1.7/aether-impl-1.7.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-repository-metadata/3.0/maven-repository-metadata-3.0.jar (30 kB at 226 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-spi/1.7/aether-spi-1.7.jar&#xA;Progress (2): 38 kB | 4.1/51 kB&#xD;Progress (2): 38 kB | 7.7/51 kB&#xD;Progress (2): 38 kB | 12/51 kB &#xD;Progress (2): 38 kB | 16/51 kB&#xD;Progress (2): 38 kB | 20/51 kB&#xD;Progress (2): 38 kB | 24/51 kB&#xD;Progress (2): 38 kB | 28/51 kB&#xD;Progress (2): 38 kB | 32/51 kB&#xD;Progress (2): 38 kB | 36/51 kB&#xD;Progress (2): 38 kB | 40/51 kB&#xD;Progress (2): 38 kB | 44/51 kB&#xD;Progress (2): 38 kB | 48/51 kB&#xD;Progress (2): 38 kB | 51 kB   &#xD;                           &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-settings-builder/3.0/maven-settings-builder-3.0.jar (38 kB at 264 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-api/1.7/aether-api-1.7.jar&#xA;Progress (2): 51 kB | 4.1/14 kB&#xD;Progress (2): 51 kB | 7.7/14 kB&#xD;Progress (2): 51 kB | 12/14 kB &#xD;Progress (2): 51 kB | 14 kB   &#xD;                           &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-aether-provider/3.0/maven-aether-provider-3.0.jar (51 kB at 305 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-util/1.7/aether-util-1.7.jar&#xA;Progress (2): 14 kB | 4.1/148 kB&#xD;Progress (2): 14 kB | 7.7/148 kB&#xD;Progress (2): 14 kB | 12/148 kB &#xD;Progress (2): 14 kB | 16/148 kB&#xD;Progress (2): 14 kB | 20/148 kB&#xD;Progress (2): 14 kB | 24/148 kB&#xD;Progress (2): 14 kB | 28/148 kB&#xD;Progress (2): 14 kB | 32/148 kB&#xD;Progress (2): 14 kB | 36/148 kB&#xD;Progress (2): 14 kB | 40/148 kB&#xD;Progress (2): 14 kB | 45/148 kB&#xD;Progress (2): 14 kB | 49/148 kB&#xD;Progress (2): 14 kB | 53/148 kB&#xD;Progress (2): 14 kB | 57/148 kB&#xD;Progress (2): 14 kB | 61/148 kB&#xD;Progress (2): 14 kB | 65/148 kB&#xD;Progress (2): 14 kB | 69/148 kB&#xD;Progress (2): 14 kB | 73/148 kB&#xD;Progress (2): 14 kB | 77/148 kB&#xD;Progress (2): 14 kB | 81/148 kB&#xD;Progress (2): 14 kB | 86/148 kB&#xD;Progress (2): 14 kB | 90/148 kB&#xD;Progress (2): 14 kB | 94/148 kB&#xD;Progress (2): 14 kB | 98/148 kB&#xD;Progress (2): 14 kB | 102/148 kB&#xD;Progress (2): 14 kB | 106/148 kB&#xD;Progress (2): 14 kB | 110/148 kB&#xD;Progress (2): 14 kB | 114/148 kB&#xD;Progress (2): 14 kB | 118/148 kB&#xD;Progress (2): 14 kB | 122/148 kB&#xD;Progress (2): 14 kB | 126/148 kB&#xD;Progress (2): 14 kB | 131/148 kB&#xD;Progress (2): 14 kB | 135/148 kB&#xD;Progress (2): 14 kB | 139/148 kB&#xD;Progress (2): 14 kB | 143/148 kB&#xD;Progress (2): 14 kB | 147/148 kB&#xD;Progress (2): 14 kB | 148 kB    &#xD;                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-spi/1.7/aether-spi-1.7.jar (14 kB at 77 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.14/plexus-interpolation-1.14.jar&#xA;Progress (2): 148 kB | 4.1/74 kB&#xD;Progress (2): 148 kB | 7.7/74 kB&#xD;Progress (2): 148 kB | 12/74 kB &#xD;Progress (2): 148 kB | 16/74 kB&#xD;Progress (2): 148 kB | 20/74 kB&#xD;Progress (2): 148 kB | 24/74 kB&#xD;Progress (2): 148 kB | 28/74 kB&#xD;Progress (2): 148 kB | 32/74 kB&#xD;Progress (2): 148 kB | 36/74 kB&#xD;Progress (2): 148 kB | 40/74 kB&#xD;Progress (2): 148 kB | 45/74 kB&#xD;Progress (2): 148 kB | 49/74 kB&#xD;Progress (2): 148 kB | 53/74 kB&#xD;Progress (2): 148 kB | 57/74 kB&#xD;Progress (2): 148 kB | 61/74 kB&#xD;Progress (2): 148 kB | 65/74 kB&#xD;Progress (2): 148 kB | 69/74 kB&#xD;Progress (2): 148 kB | 73/74 kB&#xD;Progress (2): 148 kB | 74 kB   &#xD;                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-model-builder/3.0/maven-model-builder-3.0.jar (148 kB at 759 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-classworlds/2.2.3/plexus-classworlds-2.2.3.jar&#xA;Progress (2): 74 kB | 4.1/108 kB&#xD;Progress (2): 74 kB | 7.7/108 kB&#xD;Progress (2): 74 kB | 12/108 kB &#xD;Progress (2): 74 kB | 16/108 kB&#xD;Progress (2): 74 kB | 20/108 kB&#xD;Progress (2): 74 kB | 24/108 kB&#xD;Progress (2): 74 kB | 28/108 kB&#xD;Progress (2): 74 kB | 32/108 kB&#xD;Progress (2): 74 kB | 36/108 kB&#xD;Progress (2): 74 kB | 40/108 kB&#xD;Progress (2): 74 kB | 45/108 kB&#xD;Progress (2): 74 kB | 49/108 kB&#xD;Progress (2): 74 kB | 53/108 kB&#xD;Progress (2): 74 kB | 57/108 kB&#xD;Progress (2): 74 kB | 61/108 kB&#xD;Progress (2): 74 kB | 65/108 kB&#xD;Progress (2): 74 kB | 69/108 kB&#xD;Progress (2): 74 kB | 73/108 kB&#xD;Progress (2): 74 kB | 77/108 kB&#xD;Progress (2): 74 kB | 81/108 kB&#xD;Progress (2): 74 kB | 86/108 kB&#xD;Progress (2): 74 kB | 90/108 kB&#xD;Progress (2): 74 kB | 94/108 kB&#xD;Progress (2): 74 kB | 98/108 kB&#xD;Progress (2): 74 kB | 102/108 kB&#xD;Progress (2): 74 kB | 106/108 kB&#xD;Progress (2): 74 kB | 108 kB    &#xD;Progress (3): 74 kB | 108 kB | 4.1/61 kB&#xD;Progress (3): 74 kB | 108 kB | 7.7/61 kB&#xD;Progress (3): 74 kB | 108 kB | 12/61 kB &#xD;Progress (3): 74 kB | 108 kB | 16/61 kB&#xD;Progress (3): 74 kB | 108 kB | 20/61 kB&#xD;Progress (3): 74 kB | 108 kB | 24/61 kB&#xD;Progress (3): 74 kB | 108 kB | 28/61 kB&#xD;Progress (3): 74 kB | 108 kB | 32/61 kB&#xD;Progress (3): 74 kB | 108 kB | 36/61 kB&#xD;Progress (3): 74 kB | 108 kB | 40/61 kB&#xD;Progress (3): 74 kB | 108 kB | 45/61 kB&#xD;Progress (3): 74 kB | 108 kB | 49/61 kB&#xD;Progress (3): 74 kB | 108 kB | 53/61 kB&#xD;Progress (3): 74 kB | 108 kB | 57/61 kB&#xD;Progress (3): 74 kB | 108 kB | 61/61 kB&#xD;Progress (3): 74 kB | 108 kB | 61 kB   &#xD;                                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-api/1.7/aether-api-1.7.jar (74 kB at 339 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-component-annotations/2.0.0/plexus-component-annotations-2.0.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-util/1.7/aether-util-1.7.jar (108 kB at 484 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-sec-dispatcher/1.3/plexus-sec-dispatcher-1.3.jar&#xA;Progress (2): 61 kB | 4.1/46 kB&#xD;Progress (2): 61 kB | 7.7/46 kB&#xD;Progress (2): 61 kB | 12/46 kB &#xD;                              &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-interpolation/1.14/plexus-interpolation-1.14.jar (61 kB at 267 kB/s)&#xA;Progress (1): 16/46 kB&#xD;                      &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-cipher/1.4/plexus-cipher-1.4.jar&#xA;Progress (1): 20/46 kB&#xD;Progress (1): 24/46 kB&#xD;Progress (1): 28/46 kB&#xD;Progress (1): 32/46 kB&#xD;Progress (1): 36/46 kB&#xD;Progress (1): 40/46 kB&#xD;Progress (1): 45/46 kB&#xD;Progress (1): 46 kB   &#xD;Progress (2): 46 kB | 4.1/106 kB&#xD;Progress (2): 46 kB | 7.7/106 kB&#xD;Progress (2): 46 kB | 12/106 kB &#xD;Progress (2): 46 kB | 16/106 kB&#xD;Progress (2): 46 kB | 20/106 kB&#xD;Progress (2): 46 kB | 24/106 kB&#xD;Progress (3): 46 kB | 24/106 kB | 4.1/29 kB&#xD;Progress (3): 46 kB | 24/106 kB | 7.7/29 kB&#xD;Progress (3): 46 kB | 24/106 kB | 12/29 kB &#xD;Progress (3): 46 kB | 24/106 kB | 16/29 kB&#xD;Progress (3): 46 kB | 24/106 kB | 20/29 kB&#xD;Progress (3): 46 kB | 24/106 kB | 24/29 kB&#xD;Progress (3): 46 kB | 24/106 kB | 28/29 kB&#xD;Progress (3): 46 kB | 24/106 kB | 29 kB   &#xD;                                       &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-classworlds/2.2.3/plexus-classworlds-2.2.3.jar (46 kB at 185 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/3.0/maven-artifact-3.0.jar&#xA;Progress (2): 28/106 kB | 29 kB&#xD;Progress (2): 32/106 kB | 29 kB&#xD;Progress (2): 36/106 kB | 29 kB&#xD;Progress (2): 40/106 kB | 29 kB&#xD;Progress (2): 45/106 kB | 29 kB&#xD;Progress (2): 49/106 kB | 29 kB&#xD;Progress (2): 53/106 kB | 29 kB&#xD;Progress (2): 57/106 kB | 29 kB&#xD;Progress (2): 61/106 kB | 29 kB&#xD;Progress (2): 65/106 kB | 29 kB&#xD;Progress (2): 69/106 kB | 29 kB&#xD;Progress (2): 73/106 kB | 29 kB&#xD;Progress (2): 77/106 kB | 29 kB&#xD;Progress (2): 81/106 kB | 29 kB&#xD;Progress (2): 86/106 kB | 29 kB&#xD;Progress (2): 90/106 kB | 29 kB&#xD;Progress (2): 94/106 kB | 29 kB&#xD;Progress (2): 98/106 kB | 29 kB&#xD;Progress (2): 102/106 kB | 29 kB&#xD;Progress (2): 106/106 kB | 29 kB&#xD;Progress (2): 106 kB | 29 kB    &#xD;Progress (3): 106 kB | 29 kB | 4.1/13 kB&#xD;Progress (3): 106 kB | 29 kB | 7.7/13 kB&#xD;Progress (3): 106 kB | 29 kB | 12/13 kB &#xD;Progress (3): 106 kB | 29 kB | 13 kB   &#xD;Progress (4): 106 kB | 29 kB | 13 kB | 4.1/4.2 kB&#xD;Progress (4): 106 kB | 29 kB | 13 kB | 4.2 kB    &#xD;                                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-sec-dispatcher/1.3/plexus-sec-dispatcher-1.3.jar (29 kB at 106 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.3.0/plexus-utils-3.3.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-component-annotations/2.0.0/plexus-component-annotations-2.0.0.jar (4.2 kB at 15 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-artifact-transfer/0.12.0/maven-artifact-transfer-0.12.0.jar&#xA;Progress (3): 106 kB | 13 kB | 4.1/52 kB&#xD;Progress (3): 106 kB | 13 kB | 8.2/52 kB&#xD;Progress (3): 106 kB | 13 kB | 12/52 kB &#xD;Progress (3): 106 kB | 13 kB | 16/52 kB&#xD;Progress (3): 106 kB | 13 kB | 20/52 kB&#xD;Progress (3): 106 kB | 13 kB | 25/52 kB&#xD;Progress (3): 106 kB | 13 kB | 29/52 kB&#xD;Progress (3): 106 kB | 13 kB | 33/52 kB&#xD;Progress (3): 106 kB | 13 kB | 37/52 kB&#xD;Progress (3): 106 kB | 13 kB | 41/52 kB&#xD;Progress (3): 106 kB | 13 kB | 45/52 kB&#xD;Progress (3): 106 kB | 13 kB | 49/52 kB&#xD;Progress (3): 106 kB | 13 kB | 52 kB   &#xD;                                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/plexus/plexus-cipher/1.4/plexus-cipher-1.4.jar (13 kB at 47 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-common-artifact-filters/3.0.1/maven-common-artifact-filters-3.0.1.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/sonatype/aether/aether-impl/1.7/aether-impl-1.7.jar (106 kB at 364 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-utils/3.1.0/maven-shared-utils-3.1.0.jar&#xA;Progress (2): 52 kB | 4.1/263 kB&#xD;Progress (2): 52 kB | 7.7/263 kB&#xD;Progress (2): 52 kB | 12/263 kB &#xD;Progress (2): 52 kB | 16/263 kB&#xD;Progress (2): 52 kB | 20/263 kB&#xD;Progress (2): 52 kB | 24/263 kB&#xD;Progress (2): 52 kB | 28/263 kB&#xD;Progress (2): 52 kB | 32/263 kB&#xD;Progress (2): 52 kB | 36/263 kB&#xD;Progress (2): 52 kB | 40/263 kB&#xD;Progress (2): 52 kB | 45/263 kB&#xD;Progress (2): 52 kB | 49/263 kB&#xD;Progress (2): 52 kB | 53/263 kB&#xD;Progress (2): 52 kB | 57/263 kB&#xD;Progress (2): 52 kB | 61/263 kB&#xD;Progress (2): 52 kB | 65/263 kB&#xD;Progress (2): 52 kB | 69/263 kB&#xD;Progress (2): 52 kB | 73/263 kB&#xD;Progress (2): 52 kB | 77/263 kB&#xD;Progress (2): 52 kB | 81/263 kB&#xD;Progress (2): 52 kB | 85/263 kB&#xD;Progress (2): 52 kB | 89/263 kB&#xD;Progress (2): 52 kB | 93/263 kB&#xD;Progress (2): 52 kB | 98/263 kB&#xD;Progress (2): 52 kB | 102/263 kB&#xD;Progress (2): 52 kB | 106/263 kB&#xD;Progress (2): 52 kB | 110/263 kB&#xD;Progress (2): 52 kB | 114/263 kB&#xD;Progress (2): 52 kB | 118/263 kB&#xD;Progress (2): 52 kB | 122/263 kB&#xD;Progress (2): 52 kB | 126/263 kB&#xD;Progress (2): 52 kB | 130/263 kB&#xD;Progress (2): 52 kB | 134/263 kB&#xD;Progress (2): 52 kB | 139/263 kB&#xD;Progress (2): 52 kB | 143/263 kB&#xD;Progress (2): 52 kB | 147/263 kB&#xD;Progress (2): 52 kB | 151/263 kB&#xD;Progress (2): 52 kB | 155/263 kB&#xD;Progress (2): 52 kB | 159/263 kB&#xD;Progress (2): 52 kB | 163/263 kB&#xD;Progress (2): 52 kB | 167/263 kB&#xD;Progress (2): 52 kB | 171/263 kB&#xD;Progress (2): 52 kB | 175/263 kB&#xD;Progress (2): 52 kB | 179/263 kB&#xD;Progress (2): 52 kB | 184/263 kB&#xD;Progress (2): 52 kB | 188/263 kB&#xD;Progress (2): 52 kB | 192/263 kB&#xD;Progress (2): 52 kB | 196/263 kB&#xD;Progress (2): 52 kB | 200/263 kB&#xD;Progress (2): 52 kB | 204/263 kB&#xD;Progress (2): 52 kB | 208/263 kB&#xD;Progress (2): 52 kB | 212/263 kB&#xD;Progress (2): 52 kB | 216/263 kB&#xD;Progress (2): 52 kB | 220/263 kB&#xD;Progress (2): 52 kB | 225/263 kB&#xD;Progress (2): 52 kB | 229/263 kB&#xD;Progress (2): 52 kB | 233/263 kB&#xD;Progress (2): 52 kB | 237/263 kB&#xD;Progress (2): 52 kB | 241/263 kB&#xD;Progress (2): 52 kB | 245/263 kB&#xD;Progress (2): 52 kB | 249/263 kB&#xD;Progress (2): 52 kB | 253/263 kB&#xD;Progress (2): 52 kB | 257/263 kB&#xD;Progress (2): 52 kB | 261/263 kB&#xD;Progress (2): 52 kB | 263 kB    &#xD;                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-artifact/3.0/maven-artifact-3.0.jar (52 kB at 170 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-codec/commons-codec/1.11/commons-codec-1.11.jar&#xA;Progress (2): 263 kB | 4.1/120 kB&#xD;Progress (2): 263 kB | 7.7/120 kB&#xD;Progress (2): 263 kB | 12/120 kB &#xD;Progress (2): 263 kB | 16/120 kB&#xD;Progress (2): 263 kB | 20/120 kB&#xD;Progress (2): 263 kB | 24/120 kB&#xD;                                &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/codehaus/plexus/plexus-utils/3.3.0/plexus-utils-3.3.0.jar (263 kB at 810 kB/s)&#xA;Progress (1): 28/120 kB&#xD;Progress (1): 32/120 kB&#xD;                       &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.7.5/slf4j-api-1.7.5.jar&#xA;Progress (1): 36/120 kB&#xD;Progress (1): 40/120 kB&#xD;Progress (1): 45/120 kB&#xD;Progress (1): 49/120 kB&#xD;Progress (1): 53/120 kB&#xD;Progress (1): 57/120 kB&#xD;Progress (1): 61/120 kB&#xD;Progress (1): 65/120 kB&#xD;Progress (1): 69/120 kB&#xD;Progress (1): 73/120 kB&#xD;Progress (1): 77/120 kB&#xD;Progress (1): 81/120 kB&#xD;Progress (1): 86/120 kB&#xD;Progress (1): 90/120 kB&#xD;Progress (1): 93/120 kB&#xD;Progress (1): 98/120 kB&#xD;Progress (1): 102/120 kB&#xD;Progress (1): 106/120 kB&#xD;Progress (1): 110/120 kB&#xD;Progress (1): 114/120 kB&#xD;Progress (1): 118/120 kB&#xD;Progress (1): 120 kB    &#xD;Progress (2): 120 kB | 4.1/61 kB&#xD;Progress (2): 120 kB | 7.7/61 kB&#xD;Progress (2): 120 kB | 12/61 kB &#xD;Progress (2): 120 kB | 16/61 kB&#xD;Progress (2): 120 kB | 20/61 kB&#xD;Progress (2): 120 kB | 24/61 kB&#xD;Progress (2): 120 kB | 28/61 kB&#xD;Progress (2): 120 kB | 32/61 kB&#xD;Progress (2): 120 kB | 36/61 kB&#xD;Progress (2): 120 kB | 40/61 kB&#xD;Progress (2): 120 kB | 45/61 kB&#xD;Progress (2): 120 kB | 49/61 kB&#xD;Progress (2): 120 kB | 53/61 kB&#xD;Progress (2): 120 kB | 57/61 kB&#xD;Progress (2): 120 kB | 61/61 kB&#xD;Progress (2): 120 kB | 61 kB   &#xD;Progress (3): 120 kB | 61 kB | 4.1/335 kB&#xD;Progress (3): 120 kB | 61 kB | 7.7/335 kB&#xD;Progress (3): 120 kB | 61 kB | 12/335 kB &#xD;Progress (3): 120 kB | 61 kB | 16/335 kB&#xD;Progress (3): 120 kB | 61 kB | 20/335 kB&#xD;Progress (3): 120 kB | 61 kB | 24/335 kB&#xD;Progress (3): 120 kB | 61 kB | 28/335 kB&#xD;Progress (3): 120 kB | 61 kB | 32/335 kB&#xD;Progress (3): 120 kB | 61 kB | 36/335 kB&#xD;Progress (3): 120 kB | 61 kB | 40/335 kB&#xD;Progress (3): 120 kB | 61 kB | 45/335 kB&#xD;Progress (3): 120 kB | 61 kB | 49/335 kB&#xD;Progress (3): 120 kB | 61 kB | 53/335 kB&#xD;Progress (3): 120 kB | 61 kB | 57/335 kB&#xD;Progress (3): 120 kB | 61 kB | 61/335 kB&#xD;Progress (3): 120 kB | 61 kB | 65/335 kB&#xD;Progress (3): 120 kB | 61 kB | 69/335 kB&#xD;Progress (3): 120 kB | 61 kB | 73/335 kB&#xD;Progress (3): 120 kB | 61 kB | 77/335 kB&#xD;Progress (3): 120 kB | 61 kB | 81/335 kB&#xD;Progress (3): 120 kB | 61 kB | 86/335 kB&#xD;Progress (3): 120 kB | 61 kB | 90/335 kB&#xD;Progress (3): 120 kB | 61 kB | 94/335 kB&#xD;Progress (3): 120 kB | 61 kB | 98/335 kB&#xD;Progress (3): 120 kB | 61 kB | 102/335 kB&#xD;Progress (3): 120 kB | 61 kB | 106/335 kB&#xD;Progress (3): 120 kB | 61 kB | 110/335 kB&#xD;Progress (3): 120 kB | 61 kB | 114/335 kB&#xD;Progress (3): 120 kB | 61 kB | 118/335 kB&#xD;Progress (3): 120 kB | 61 kB | 122/335 kB&#xD;Progress (3): 120 kB | 61 kB | 126/335 kB&#xD;Progress (3): 120 kB | 61 kB | 131/335 kB&#xD;Progress (3): 120 kB | 61 kB | 135/335 kB&#xD;Progress (3): 120 kB | 61 kB | 139/335 kB&#xD;Progress (3): 120 kB | 61 kB | 143/335 kB&#xD;Progress (3): 120 kB | 61 kB | 147/335 kB&#xD;Progress (3): 120 kB | 61 kB | 151/335 kB&#xD;Progress (3): 120 kB | 61 kB | 155/335 kB&#xD;Progress (3): 120 kB | 61 kB | 159/335 kB&#xD;Progress (3): 120 kB | 61 kB | 163/335 kB&#xD;Progress (3): 120 kB | 61 kB | 167/335 kB&#xD;Progress (3): 120 kB | 61 kB | 172/335 kB&#xD;Progress (3): 120 kB | 61 kB | 176/335 kB&#xD;Progress (3): 120 kB | 61 kB | 180/335 kB&#xD;Progress (3): 120 kB | 61 kB | 184/335 kB&#xD;Progress (3): 120 kB | 61 kB | 188/335 kB&#xD;Progress (3): 120 kB | 61 kB | 192/335 kB&#xD;Progress (3): 120 kB | 61 kB | 196/335 kB&#xD;Progress (3): 120 kB | 61 kB | 200/335 kB&#xD;Progress (3): 120 kB | 61 kB | 204/335 kB&#xD;Progress (3): 120 kB | 61 kB | 208/335 kB&#xD;Progress (3): 120 kB | 61 kB | 213/335 kB&#xD;Progress (3): 120 kB | 61 kB | 217/335 kB&#xD;Progress (3): 120 kB | 61 kB | 221/335 kB&#xD;Progress (3): 120 kB | 61 kB | 225/335 kB&#xD;Progress (3): 120 kB | 61 kB | 229/335 kB&#xD;Progress (3): 120 kB | 61 kB | 233/335 kB&#xD;Progress (3): 120 kB | 61 kB | 237/335 kB&#xD;Progress (3): 120 kB | 61 kB | 241/335 kB&#xD;Progress (3): 120 kB | 61 kB | 245/335 kB&#xD;Progress (3): 120 kB | 61 kB | 249/335 kB&#xD;Progress (3): 120 kB | 61 kB | 253/335 kB&#xD;Progress (3): 120 kB | 61 kB | 258/335 kB&#xD;Progress (3): 120 kB | 61 kB | 262/335 kB&#xD;Progress (3): 120 kB | 61 kB | 266/335 kB&#xD;Progress (3): 120 kB | 61 kB | 270/335 kB&#xD;Progress (3): 120 kB | 61 kB | 274/335 kB&#xD;Progress (3): 120 kB | 61 kB | 278/335 kB&#xD;Progress (3): 120 kB | 61 kB | 282/335 kB&#xD;Progress (3): 120 kB | 61 kB | 286/335 kB&#xD;Progress (3): 120 kB | 61 kB | 290/335 kB&#xD;Progress (3): 120 kB | 61 kB | 294/335 kB&#xD;Progress (3): 120 kB | 61 kB | 299/335 kB&#xD;Progress (3): 120 kB | 61 kB | 303/335 kB&#xD;Progress (3): 120 kB | 61 kB | 307/335 kB&#xD;Progress (3): 120 kB | 61 kB | 311/335 kB&#xD;Progress (3): 120 kB | 61 kB | 315/335 kB&#xD;Progress (3): 120 kB | 61 kB | 319/335 kB&#xD;Progress (3): 120 kB | 61 kB | 323/335 kB&#xD;Progress (3): 120 kB | 61 kB | 327/335 kB&#xD;Progress (3): 120 kB | 61 kB | 331/335 kB&#xD;Progress (3): 120 kB | 61 kB | 335 kB    &#xD;Progress (4): 120 kB | 61 kB | 335 kB | 4.1/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 7.7/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 12/164 kB &#xD;Progress (4): 120 kB | 61 kB | 335 kB | 16/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 20/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 24/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 28/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 32/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 36/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 40/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 45/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 49/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 53/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 55/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 59/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 63/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 67/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 71/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 75/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 79/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 84/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 88/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 92/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 96/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 100/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 104/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 108/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 112/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 116/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 120/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 124/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 129/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 133/164 kB&#xD;Progress (4): 120 kB | 61 kB | 335 kB | 137/164 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 137/164 kB | 4.1/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 141/164 kB | 4.1/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 145/164 kB | 4.1/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 145/164 kB | 7.7/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 149/164 kB | 7.7/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 149/164 kB | 12/26 kB &#xD;Progress (5): 120 kB | 61 kB | 335 kB | 153/164 kB | 12/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 153/164 kB | 16/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 157/164 kB | 16/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 161/164 kB | 16/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 161/164 kB | 20/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 164 kB | 20/26 kB    &#xD;Progress (5): 120 kB | 61 kB | 335 kB | 164 kB | 24/26 kB&#xD;Progress (5): 120 kB | 61 kB | 335 kB | 164 kB | 26 kB   &#xD;                                                      &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-artifact-transfer/0.12.0/maven-artifact-transfer-0.12.0.jar (120 kB at 336 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm/8.0/asm-8.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/commons-codec/commons-codec/1.11/commons-codec-1.11.jar (335 kB at 931 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-commons/8.0/asm-commons-8.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-common-artifact-filters/3.0.1/maven-common-artifact-filters-3.0.1.jar (61 kB at 167 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-tree/8.0/asm-tree-8.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-shared-utils/3.1.0/maven-shared-utils-3.1.0.jar (164 kB at 429 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-analysis/8.0/asm-analysis-8.0.jar&#xA;Progress (2): 26 kB | 4.1/72 kB&#xD;Progress (2): 26 kB | 7.7/72 kB&#xD;Progress (2): 26 kB | 12/72 kB &#xD;Progress (2): 26 kB | 16/72 kB&#xD;Progress (2): 26 kB | 20/72 kB&#xD;Progress (2): 26 kB | 24/72 kB&#xD;Progress (2): 26 kB | 28/72 kB&#xD;Progress (2): 26 kB | 32/72 kB&#xD;Progress (2): 26 kB | 36/72 kB&#xD;Progress (2): 26 kB | 40/72 kB&#xD;Progress (2): 26 kB | 45/72 kB&#xD;Progress (2): 26 kB | 49/72 kB&#xD;Progress (2): 26 kB | 53/72 kB&#xD;Progress (2): 26 kB | 57/72 kB&#xD;Progress (2): 26 kB | 61/72 kB&#xD;Progress (2): 26 kB | 65/72 kB&#xD;Progress (2): 26 kB | 69/72 kB&#xD;Progress (2): 26 kB | 72 kB   &#xD;Progress (3): 26 kB | 72 kB | 4.1/122 kB&#xD;Progress (3): 26 kB | 72 kB | 7.7/122 kB&#xD;Progress (3): 26 kB | 72 kB | 12/122 kB &#xD;Progress (3): 26 kB | 72 kB | 16/122 kB&#xD;Progress (3): 26 kB | 72 kB | 20/122 kB&#xD;                                       &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/slf4j/slf4j-api/1.7.5/slf4j-api-1.7.5.jar (26 kB at 65 kB/s)&#xA;Progress (2): 72 kB | 24/122 kB&#xD;                               &#xD;Downloading from central: https://repo.maven.apache.org/maven2/org/jdom/jdom2/2.0.6/jdom2-2.0.6.jar&#xA;Progress (2): 72 kB | 28/122 kB&#xD;Progress (2): 72 kB | 32/122 kB&#xD;Progress (2): 72 kB | 36/122 kB&#xD;Progress (2): 72 kB | 40/122 kB&#xD;Progress (2): 72 kB | 45/122 kB&#xD;Progress (2): 72 kB | 49/122 kB&#xD;Progress (2): 72 kB | 53/122 kB&#xD;Progress (2): 72 kB | 57/122 kB&#xD;Progress (2): 72 kB | 61/122 kB&#xD;Progress (2): 72 kB | 65/122 kB&#xD;Progress (2): 72 kB | 69/122 kB&#xD;Progress (2): 72 kB | 73/122 kB&#xD;Progress (2): 72 kB | 77/122 kB&#xD;Progress (2): 72 kB | 81/122 kB&#xD;Progress (2): 72 kB | 86/122 kB&#xD;Progress (2): 72 kB | 90/122 kB&#xD;Progress (2): 72 kB | 94/122 kB&#xD;Progress (2): 72 kB | 98/122 kB&#xD;Progress (2): 72 kB | 102/122 kB&#xD;Progress (2): 72 kB | 106/122 kB&#xD;Progress (2): 72 kB | 110/122 kB&#xD;Progress (2): 72 kB | 114/122 kB&#xD;Progress (2): 72 kB | 118/122 kB&#xD;Progress (2): 72 kB | 122 kB    &#xD;                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-commons/8.0/asm-commons-8.0.jar (72 kB at 175 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-dependency-tree/3.0.1/maven-dependency-tree-3.0.1.jar&#xA;Progress (2): 122 kB | 4.1/33 kB&#xD;Progress (2): 122 kB | 7.7/33 kB&#xD;Progress (2): 122 kB | 12/33 kB &#xD;Progress (2): 122 kB | 16/33 kB&#xD;Progress (2): 122 kB | 20/33 kB&#xD;Progress (2): 122 kB | 24/33 kB&#xD;Progress (2): 122 kB | 28/33 kB&#xD;Progress (2): 122 kB | 32/33 kB&#xD;Progress (2): 122 kB | 33 kB   &#xD;Progress (3): 122 kB | 33 kB | 4.1/53 kB&#xD;Progress (3): 122 kB | 33 kB | 7.7/53 kB&#xD;Progress (3): 122 kB | 33 kB | 12/53 kB &#xD;Progress (3): 122 kB | 33 kB | 16/53 kB&#xD;Progress (3): 122 kB | 33 kB | 20/53 kB&#xD;Progress (3): 122 kB | 33 kB | 24/53 kB&#xD;Progress (3): 122 kB | 33 kB | 28/53 kB&#xD;Progress (3): 122 kB | 33 kB | 32/53 kB&#xD;Progress (3): 122 kB | 33 kB | 36/53 kB&#xD;Progress (3): 122 kB | 33 kB | 40/53 kB&#xD;Progress (3): 122 kB | 33 kB | 45/53 kB&#xD;Progress (3): 122 kB | 33 kB | 49/53 kB&#xD;Progress (3): 122 kB | 33 kB | 53 kB   &#xD;Progress (4): 122 kB | 33 kB | 53 kB | 4.1/37 kB&#xD;Progress (4): 122 kB | 33 kB | 53 kB | 7.7/37 kB&#xD;Progress (4): 122 kB | 33 kB | 53 kB | 12/37 kB &#xD;Progress (4): 122 kB | 33 kB | 53 kB | 16/37 kB&#xD;Progress (4): 122 kB | 33 kB | 53 kB | 20/37 kB&#xD;Progress (4): 122 kB | 33 kB | 53 kB | 24/37 kB&#xD;Progress (4): 122 kB | 33 kB | 53 kB | 28/37 kB&#xD;Progress (4): 122 kB | 33 kB | 53 kB | 32/37 kB&#xD;Progress (4): 122 kB | 33 kB | 53 kB | 36/37 kB&#xD;Progress (4): 122 kB | 33 kB | 53 kB | 37 kB   &#xD;                                            &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm/8.0/asm-8.0.jar (122 kB at 275 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/eclipse/aether/aether-util/0.9.0.M2/aether-util-0.9.0.M2.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-analysis/8.0/asm-analysis-8.0.jar (33 kB at 75 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.6/commons-io-2.6.jar&#xA;Progress (3): 53 kB | 37 kB | 4.1/305 kB&#xD;Progress (3): 53 kB | 37 kB | 7.7/305 kB&#xD;Progress (3): 53 kB | 37 kB | 12/305 kB &#xD;Progress (3): 53 kB | 37 kB | 16/305 kB&#xD;Progress (3): 53 kB | 37 kB | 20/305 kB&#xD;Progress (3): 53 kB | 37 kB | 24/305 kB&#xD;Progress (3): 53 kB | 37 kB | 28/305 kB&#xD;Progress (3): 53 kB | 37 kB | 32/305 kB&#xD;Progress (3): 53 kB | 37 kB | 36/305 kB&#xD;Progress (3): 53 kB | 37 kB | 40/305 kB&#xD;Progress (3): 53 kB | 37 kB | 45/305 kB&#xD;Progress (3): 53 kB | 37 kB | 49/305 kB&#xD;Progress (3): 53 kB | 37 kB | 53/305 kB&#xD;Progress (3): 53 kB | 37 kB | 57/305 kB&#xD;Progress (3): 53 kB | 37 kB | 61/305 kB&#xD;Progress (3): 53 kB | 37 kB | 65/305 kB&#xD;Progress (3): 53 kB | 37 kB | 69/305 kB&#xD;Progress (3): 53 kB | 37 kB | 73/305 kB&#xD;Progress (3): 53 kB | 37 kB | 77/305 kB&#xD;Progress (3): 53 kB | 37 kB | 81/305 kB&#xD;Progress (3): 53 kB | 37 kB | 86/305 kB&#xD;Progress (3): 53 kB | 37 kB | 90/305 kB&#xD;Progress (3): 53 kB | 37 kB | 94/305 kB&#xD;Progress (3): 53 kB | 37 kB | 98/305 kB&#xD;Progress (3): 53 kB | 37 kB | 102/305 kB&#xD;Progress (3): 53 kB | 37 kB | 106/305 kB&#xD;Progress (3): 53 kB | 37 kB | 110/305 kB&#xD;Progress (3): 53 kB | 37 kB | 114/305 kB&#xD;Progress (3): 53 kB | 37 kB | 118/305 kB&#xD;Progress (3): 53 kB | 37 kB | 122/305 kB&#xD;Progress (3): 53 kB | 37 kB | 126/305 kB&#xD;Progress (3): 53 kB | 37 kB | 131/305 kB&#xD;Progress (3): 53 kB | 37 kB | 135/305 kB&#xD;Progress (3): 53 kB | 37 kB | 139/305 kB&#xD;Progress (3): 53 kB | 37 kB | 143/305 kB&#xD;Progress (3): 53 kB | 37 kB | 147/305 kB&#xD;Progress (3): 53 kB | 37 kB | 151/305 kB&#xD;Progress (3): 53 kB | 37 kB | 155/305 kB&#xD;Progress (3): 53 kB | 37 kB | 159/305 kB&#xD;Progress (3): 53 kB | 37 kB | 163/305 kB&#xD;Progress (3): 53 kB | 37 kB | 167/305 kB&#xD;Progress (3): 53 kB | 37 kB | 172/305 kB&#xD;Progress (3): 53 kB | 37 kB | 176/305 kB&#xD;Progress (3): 53 kB | 37 kB | 180/305 kB&#xD;Progress (3): 53 kB | 37 kB | 184/305 kB&#xD;Progress (3): 53 kB | 37 kB | 188/305 kB&#xD;Progress (3): 53 kB | 37 kB | 192/305 kB&#xD;Progress (3): 53 kB | 37 kB | 196/305 kB&#xD;Progress (3): 53 kB | 37 kB | 200/305 kB&#xD;Progress (3): 53 kB | 37 kB | 204/305 kB&#xD;Progress (3): 53 kB | 37 kB | 208/305 kB&#xD;Progress (3): 53 kB | 37 kB | 213/305 kB&#xD;Progress (3): 53 kB | 37 kB | 217/305 kB&#xD;Progress (3): 53 kB | 37 kB | 221/305 kB&#xD;Progress (3): 53 kB | 37 kB | 225/305 kB&#xD;Progress (3): 53 kB | 37 kB | 229/305 kB&#xD;Progress (3): 53 kB | 37 kB | 233/305 kB&#xD;Progress (3): 53 kB | 37 kB | 237/305 kB&#xD;Progress (3): 53 kB | 37 kB | 241/305 kB&#xD;Progress (3): 53 kB | 37 kB | 245/305 kB&#xD;Progress (3): 53 kB | 37 kB | 249/305 kB&#xD;Progress (3): 53 kB | 37 kB | 253/305 kB&#xD;Progress (3): 53 kB | 37 kB | 258/305 kB&#xD;Progress (3): 53 kB | 37 kB | 262/305 kB&#xD;Progress (3): 53 kB | 37 kB | 266/305 kB&#xD;Progress (3): 53 kB | 37 kB | 270/305 kB&#xD;Progress (3): 53 kB | 37 kB | 274/305 kB&#xD;Progress (3): 53 kB | 37 kB | 278/305 kB&#xD;Progress (3): 53 kB | 37 kB | 282/305 kB&#xD;Progress (3): 53 kB | 37 kB | 286/305 kB&#xD;Progress (3): 53 kB | 37 kB | 290/305 kB&#xD;Progress (3): 53 kB | 37 kB | 294/305 kB&#xD;Progress (3): 53 kB | 37 kB | 299/305 kB&#xD;Progress (3): 53 kB | 37 kB | 303/305 kB&#xD;Progress (3): 53 kB | 37 kB | 305 kB    &#xD;                                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-tree/8.0/asm-tree-8.0.jar (53 kB at 113 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/vafer/jdependency/2.4.0/jdependency-2.4.0.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/shared/maven-dependency-tree/3.0.1/maven-dependency-tree-3.0.1.jar (37 kB at 78 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-util/8.0/asm-util-8.0.jar&#xA;Progress (2): 305 kB | 4.1/215 kB&#xD;Progress (2): 305 kB | 7.7/215 kB&#xD;Progress (2): 305 kB | 12/215 kB &#xD;Progress (2): 305 kB | 16/215 kB&#xD;Progress (2): 305 kB | 20/215 kB&#xD;Progress (2): 305 kB | 24/215 kB&#xD;Progress (2): 305 kB | 28/215 kB&#xD;Progress (2): 305 kB | 32/215 kB&#xD;Progress (2): 305 kB | 36/215 kB&#xD;Progress (2): 305 kB | 40/215 kB&#xD;Progress (2): 305 kB | 45/215 kB&#xD;Progress (2): 305 kB | 49/215 kB&#xD;Progress (2): 305 kB | 53/215 kB&#xD;Progress (2): 305 kB | 57/215 kB&#xD;Progress (2): 305 kB | 61/215 kB&#xD;Progress (2): 305 kB | 65/215 kB&#xD;Progress (2): 305 kB | 69/215 kB&#xD;Progress (2): 305 kB | 73/215 kB&#xD;Progress (2): 305 kB | 77/215 kB&#xD;Progress (2): 305 kB | 81/215 kB&#xD;Progress (2): 305 kB | 86/215 kB&#xD;Progress (2): 305 kB | 90/215 kB&#xD;Progress (2): 305 kB | 94/215 kB&#xD;Progress (2): 305 kB | 98/215 kB&#xD;Progress (2): 305 kB | 102/215 kB&#xD;Progress (2): 305 kB | 106/215 kB&#xD;Progress (2): 305 kB | 110/215 kB&#xD;Progress (2): 305 kB | 114/215 kB&#xD;Progress (2): 305 kB | 118/215 kB&#xD;Progress (2): 305 kB | 122/215 kB&#xD;Progress (2): 305 kB | 126/215 kB&#xD;Progress (2): 305 kB | 131/215 kB&#xD;Progress (3): 305 kB | 131/215 kB | 4.1/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 7.7/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 12/134 kB &#xD;Progress (3): 305 kB | 131/215 kB | 16/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 20/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 24/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 28/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 32/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 36/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 40/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 45/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 49/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 53/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 57/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 61/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 65/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 69/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 73/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 77/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 81/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 86/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 90/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 94/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 98/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 102/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 106/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 110/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 114/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 118/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 122/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 126/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 131/134 kB&#xD;Progress (3): 305 kB | 131/215 kB | 134 kB    &#xD;Progress (3): 305 kB | 135/215 kB | 134 kB&#xD;Progress (3): 305 kB | 139/215 kB | 134 kB&#xD;Progress (3): 305 kB | 143/215 kB | 134 kB&#xD;Progress (3): 305 kB | 147/215 kB | 134 kB&#xD;Progress (3): 305 kB | 151/215 kB | 134 kB&#xD;Progress (3): 305 kB | 155/215 kB | 134 kB&#xD;Progress (3): 305 kB | 159/215 kB | 134 kB&#xD;Progress (3): 305 kB | 163/215 kB | 134 kB&#xD;Progress (3): 305 kB | 167/215 kB | 134 kB&#xD;Progress (3): 305 kB | 172/215 kB | 134 kB&#xD;Progress (3): 305 kB | 176/215 kB | 134 kB&#xD;Progress (3): 305 kB | 180/215 kB | 134 kB&#xD;Progress (3): 305 kB | 184/215 kB | 134 kB&#xD;Progress (3): 305 kB | 188/215 kB | 134 kB&#xD;Progress (3): 305 kB | 192/215 kB | 134 kB&#xD;Progress (3): 305 kB | 196/215 kB | 134 kB&#xD;Progress (3): 305 kB | 200/215 kB | 134 kB&#xD;Progress (3): 305 kB | 204/215 kB | 134 kB&#xD;Progress (3): 305 kB | 208/215 kB | 134 kB&#xD;Progress (3): 305 kB | 213/215 kB | 134 kB&#xD;Progress (3): 305 kB | 215 kB | 134 kB    &#xD;                                      &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/jdom/jdom2/2.0.6/jdom2-2.0.6.jar (305 kB at 610 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/guava/guava/28.2-android/guava-28.2-android.jar&#xA;Progress (3): 215 kB | 134 kB | 4.1/85 kB&#xD;Progress (3): 215 kB | 134 kB | 7.7/85 kB&#xD;Progress (3): 215 kB | 134 kB | 12/85 kB &#xD;Progress (3): 215 kB | 134 kB | 16/85 kB&#xD;Progress (3): 215 kB | 134 kB | 20/85 kB&#xD;Progress (3): 215 kB | 134 kB | 24/85 kB&#xD;Progress (3): 215 kB | 134 kB | 28/85 kB&#xD;Progress (3): 215 kB | 134 kB | 32/85 kB&#xD;Progress (3): 215 kB | 134 kB | 36/85 kB&#xD;Progress (3): 215 kB | 134 kB | 40/85 kB&#xD;Progress (3): 215 kB | 134 kB | 45/85 kB&#xD;Progress (3): 215 kB | 134 kB | 49/85 kB&#xD;Progress (3): 215 kB | 134 kB | 53/85 kB&#xD;Progress (3): 215 kB | 134 kB | 57/85 kB&#xD;Progress (3): 215 kB | 134 kB | 61/85 kB&#xD;Progress (3): 215 kB | 134 kB | 65/85 kB&#xD;Progress (3): 215 kB | 134 kB | 69/85 kB&#xD;Progress (3): 215 kB | 134 kB | 73/85 kB&#xD;Progress (3): 215 kB | 134 kB | 77/85 kB&#xD;Progress (3): 215 kB | 134 kB | 81/85 kB&#xD;Progress (3): 215 kB | 134 kB | 85 kB   &#xD;Progress (4): 215 kB | 134 kB | 85 kB | 4.1/180 kB&#xD;Progress (4): 215 kB | 134 kB | 85 kB | 7.7/180 kB&#xD;Progress (4): 215 kB | 134 kB | 85 kB | 12/180 kB &#xD;Progress (4): 215 kB | 134 kB | 85 kB | 16/180 kB&#xD;Progress (4): 215 kB | 134 kB | 85 kB | 20/180 kB&#xD;Progress (4): 215 kB | 134 kB | 85 kB | 24/180 kB&#xD;Progress (4): 215 kB | 134 kB | 85 kB | 28/180 kB&#xD;Progress (4): 215 kB | 134 kB | 85 kB | 32/180 kB&#xD;Progress (4): 215 kB | 134 kB | 85 kB | 36/180 kB&#xD;Progress (4): 215 kB | 134 kB | 85 kB | 40/180 kB&#xD;                                                 &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/commons-io/commons-io/2.6/commons-io-2.6.jar (215 kB at 418 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/guava/failureaccess/1.0.1/failureaccess-1.0.1.jar&#xA;Progress (3): 134 kB | 85 kB | 45/180 kB&#xD;Progress (3): 134 kB | 85 kB | 49/180 kB&#xD;Progress (3): 134 kB | 85 kB | 53/180 kB&#xD;Progress (3): 134 kB | 85 kB | 57/180 kB&#xD;Progress (3): 134 kB | 85 kB | 61/180 kB&#xD;Progress (3): 134 kB | 85 kB | 65/180 kB&#xD;Progress (3): 134 kB | 85 kB | 69/180 kB&#xD;Progress (3): 134 kB | 85 kB | 73/180 kB&#xD;                                        &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/eclipse/aether/aether-util/0.9.0.M2/aether-util-0.9.0.M2.jar (134 kB at 259 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/guava/listenablefuture/9999.0-empty-to-avoid-conflict-with-guava/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar&#xA;Progress (2): 85 kB | 77/180 kB&#xD;Progress (2): 85 kB | 81/180 kB&#xD;Progress (2): 85 kB | 86/180 kB&#xD;Progress (2): 85 kB | 90/180 kB&#xD;Progress (2): 85 kB | 94/180 kB&#xD;Progress (2): 85 kB | 98/180 kB&#xD;Progress (2): 85 kB | 102/180 kB&#xD;Progress (2): 85 kB | 106/180 kB&#xD;Progress (2): 85 kB | 110/180 kB&#xD;Progress (2): 85 kB | 114/180 kB&#xD;Progress (2): 85 kB | 118/180 kB&#xD;Progress (2): 85 kB | 122/180 kB&#xD;Progress (2): 85 kB | 126/180 kB&#xD;Progress (2): 85 kB | 131/180 kB&#xD;Progress (2): 85 kB | 135/180 kB&#xD;Progress (2): 85 kB | 139/180 kB&#xD;Progress (2): 85 kB | 143/180 kB&#xD;Progress (2): 85 kB | 147/180 kB&#xD;Progress (2): 85 kB | 151/180 kB&#xD;Progress (2): 85 kB | 155/180 kB&#xD;Progress (2): 85 kB | 159/180 kB&#xD;Progress (2): 85 kB | 163/180 kB&#xD;Progress (2): 85 kB | 167/180 kB&#xD;Progress (2): 85 kB | 172/180 kB&#xD;Progress (2): 85 kB | 176/180 kB&#xD;Progress (2): 85 kB | 180/180 kB&#xD;Progress (2): 85 kB | 180 kB    &#xD;Progress (3): 85 kB | 180 kB | 4.1/4.6 kB&#xD;Progress (3): 85 kB | 180 kB | 4.6 kB    &#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.1/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.1/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.1/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.1/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.1/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.1/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.2/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.2/2.6 MB&#xD;Progress (4): 85 kB | 180 kB | 4.6 kB | 0.2/2.6 MB&#xD;                                                  &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/ow2/asm/asm-util/8.0/asm-util-8.0.jar (85 kB at 155 kB/s)&#xA;Progress (4): 180 kB | 4.6 kB | 0.2/2.6 MB | 2.2 kB&#xD;                                                   &#xD;Downloading from central: https://repo.maven.apache.org/maven2/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar&#xA;Progress (4): 180 kB | 4.6 kB | 0.2/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.2/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.2/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.3/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.3/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.3/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.3/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.3/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.3/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.4/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.4/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.4/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.4/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.4/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.4/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.5/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.5/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.5/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.5/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.5/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.5/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.6/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.6/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.6/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.6/2.6 MB | 2.2 kB&#xD;Progress (4): 180 kB | 4.6 kB | 0.6/2.6 MB | 2.2 kB&#xD;                                                   &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/vafer/jdependency/2.4.0/jdependency-2.4.0.jar (180 kB at 324 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/checkerframework/checker-compat-qual/2.5.5/checker-compat-qual-2.5.5.jar&#xA;Progress (3): 4.6 kB | 0.6/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.7/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.7/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.7/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.7/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.7/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.7/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.8/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.8/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.8/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.8/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.8/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.8/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.9/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.9/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.9/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.9/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.9/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.9/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 0.9/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.0/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.0/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.0/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.0/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.0/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.0/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.1/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.1/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.1/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.1/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.1/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.1/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.2/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.2/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.2/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.2/2.6 MB | 2.2 kB&#xD;Progress (3): 4.6 kB | 1.2/2.6 MB | 2.2 kB&#xD;                                          &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/guava/failureaccess/1.0.1/failureaccess-1.0.1.jar (4.6 kB at 8.2 kB/s)&#xA;Progress (2): 1.2/2.6 MB | 2.2 kB&#xD;Progress (2): 1.3/2.6 MB | 2.2 kB&#xD;                                 &#xD;Downloading from central: https://repo.maven.apache.org/maven2/com/google/errorprone/error_prone_annotations/2.3.4/error_prone_annotations-2.3.4.jar&#xA;Progress (2): 1.3/2.6 MB | 2.2 kB&#xD;Progress (2): 1.3/2.6 MB | 2.2 kB&#xD;Progress (2): 1.3/2.6 MB | 2.2 kB&#xD;Progress (2): 1.3/2.6 MB | 2.2 kB&#xD;Progress (2): 1.3/2.6 MB | 2.2 kB&#xD;Progress (2): 1.4/2.6 MB | 2.2 kB&#xD;Progress (2): 1.4/2.6 MB | 2.2 kB&#xD;Progress (2): 1.4/2.6 MB | 2.2 kB&#xD;Progress (2): 1.4/2.6 MB | 2.2 kB&#xD;Progress (2): 1.4/2.6 MB | 2.2 kB&#xD;Progress (2): 1.4/2.6 MB | 2.2 kB&#xD;Progress (2): 1.5/2.6 MB | 2.2 kB&#xD;Progress (2): 1.5/2.6 MB | 2.2 kB&#xD;Progress (2): 1.5/2.6 MB | 2.2 kB&#xD;Progress (2): 1.5/2.6 MB | 2.2 kB&#xD;Progress (2): 1.5/2.6 MB | 2.2 kB&#xD;Progress (2): 1.5/2.6 MB | 2.2 kB&#xD;Progress (2): 1.5/2.6 MB | 2.2 kB&#xD;Progress (2): 1.6/2.6 MB | 2.2 kB&#xD;Progress (2): 1.6/2.6 MB | 2.2 kB&#xD;Progress (2): 1.6/2.6 MB | 2.2 kB&#xD;Progress (2): 1.6/2.6 MB | 2.2 kB&#xD;Progress (2): 1.6/2.6 MB | 2.2 kB&#xD;Progress (2): 1.6/2.6 MB | 2.2 kB&#xD;Progress (2): 1.7/2.6 MB | 2.2 kB&#xD;Progress (2): 1.7/2.6 MB | 2.2 kB&#xD;Progress (2): 1.7/2.6 MB | 2.2 kB&#xD;Progress (2): 1.7/2.6 MB | 2.2 kB&#xD;Progress (2): 1.7/2.6 MB | 2.2 kB&#xD;Progress (2): 1.7/2.6 MB | 2.2 kB&#xD;Progress (2): 1.8/2.6 MB | 2.2 kB&#xD;Progress (2): 1.8/2.6 MB | 2.2 kB&#xD;Progress (2): 1.8/2.6 MB | 2.2 kB&#xD;Progress (2): 1.8/2.6 MB | 2.2 kB&#xD;Progress (2): 1.8/2.6 MB | 2.2 kB&#xD;Progress (2): 1.8/2.6 MB | 2.2 kB&#xD;Progress (2): 1.9/2.6 MB | 2.2 kB&#xD;Progress (2): 1.9/2.6 MB | 2.2 kB&#xD;Progress (2): 1.9/2.6 MB | 2.2 kB&#xD;Progress (2): 1.9/2.6 MB | 2.2 kB&#xD;Progress (2): 1.9/2.6 MB | 2.2 kB&#xD;Progress (2): 1.9/2.6 MB | 2.2 kB&#xD;Progress (2): 2.0/2.6 MB | 2.2 kB&#xD;Progress (2): 2.0/2.6 MB | 2.2 kB&#xD;Progress (2): 2.0/2.6 MB | 2.2 kB&#xD;Progress (2): 2.0/2.6 MB | 2.2 kB&#xD;Progress (2): 2.0/2.6 MB | 2.2 kB&#xD;Progress (2): 2.0/2.6 MB | 2.2 kB&#xD;Progress (2): 2.1/2.6 MB | 2.2 kB&#xD;Progress (2): 2.1/2.6 MB | 2.2 kB&#xD;Progress (2): 2.1/2.6 MB | 2.2 kB&#xD;Progress (2): 2.1/2.6 MB | 2.2 kB&#xD;Progress (2): 2.1/2.6 MB | 2.2 kB&#xD;Progress (2): 2.1/2.6 MB | 2.2 kB&#xD;Progress (2): 2.2/2.6 MB | 2.2 kB&#xD;Progress (2): 2.2/2.6 MB | 2.2 kB&#xD;Progress (2): 2.2/2.6 MB | 2.2 kB&#xD;Progress (2): 2.2/2.6 MB | 2.2 kB&#xD;Progress (2): 2.2/2.6 MB | 2.2 kB&#xD;Progress (2): 2.2/2.6 MB | 2.2 kB&#xD;Progress (2): 2.2/2.6 MB | 2.2 kB&#xD;Progress (2): 2.3/2.6 MB | 2.2 kB&#xD;Progress (2): 2.3/2.6 MB | 2.2 kB&#xD;Progress (2): 2.3/2.6 MB | 2.2 kB&#xD;Progress (2): 2.3/2.6 MB | 2.2 kB&#xD;Progress (2): 2.3/2.6 MB | 2.2 kB&#xD;Progress (2): 2.3/2.6 MB | 2.2 kB&#xD;Progress (2): 2.4/2.6 MB | 2.2 kB&#xD;Progress (2): 2.4/2.6 MB | 2.2 kB&#xD;Progress (2): 2.4/2.6 MB | 2.2 kB&#xD;Progress (2): 2.4/2.6 MB | 2.2 kB&#xD;Progress (2): 2.4/2.6 MB | 2.2 kB&#xD;Progress (2): 2.4/2.6 MB | 2.2 kB&#xD;Progress (2): 2.5/2.6 MB | 2.2 kB&#xD;Progress (2): 2.5/2.6 MB | 2.2 kB&#xD;Progress (2): 2.5/2.6 MB | 2.2 kB&#xD;Progress (2): 2.5/2.6 MB | 2.2 kB&#xD;Progress (2): 2.5/2.6 MB | 2.2 kB&#xD;Progress (2): 2.5/2.6 MB | 2.2 kB&#xD;Progress (2): 2.6/2.6 MB | 2.2 kB&#xD;Progress (2): 2.6/2.6 MB | 2.2 kB&#xD;Progress (2): 2.6/2.6 MB | 2.2 kB&#xD;Progress (2): 2.6/2.6 MB | 2.2 kB&#xD;Progress (2): 2.6/2.6 MB | 2.2 kB&#xD;Progress (2): 2.6 MB | 2.2 kB    &#xD;                             &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/guava/listenablefuture/9999.0-empty-to-avoid-conflict-with-guava/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar (2.2 kB at 3.8 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/com/google/j2objc/j2objc-annotations/1.3/j2objc-annotations-1.3.jar&#xA;Progress (2): 2.6 MB | 4.1/20 kB&#xD;Progress (2): 2.6 MB | 7.7/20 kB&#xD;Progress (2): 2.6 MB | 12/20 kB &#xD;Progress (2): 2.6 MB | 16/20 kB&#xD;Progress (2): 2.6 MB | 20 kB   &#xD;Progress (3): 2.6 MB | 20 kB | 4.1/5.9 kB&#xD;Progress (3): 2.6 MB | 20 kB | 5.9 kB    &#xD;Progress (4): 2.6 MB | 20 kB | 5.9 kB | 4.1/14 kB&#xD;Progress (4): 2.6 MB | 20 kB | 5.9 kB | 7.7/14 kB&#xD;Progress (4): 2.6 MB | 20 kB | 5.9 kB | 12/14 kB &#xD;Progress (4): 2.6 MB | 20 kB | 5.9 kB | 14 kB   &#xD;Progress (5): 2.6 MB | 20 kB | 5.9 kB | 14 kB | 4.1/8.8 kB&#xD;Progress (5): 2.6 MB | 20 kB | 5.9 kB | 14 kB | 7.7/8.8 kB&#xD;Progress (5): 2.6 MB | 20 kB | 5.9 kB | 14 kB | 8.8 kB    &#xD;                                                      &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar (20 kB at 32 kB/s)&#xA;Downloading from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-lang3/3.7/commons-lang3-3.7.jar&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/org/checkerframework/checker-compat-qual/2.5.5/checker-compat-qual-2.5.5.jar (5.9 kB at 9.4 kB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/guava/guava/28.2-android/guava-28.2-android.jar (2.6 MB at 4.2 MB/s)&#xA;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/errorprone/error_prone_annotations/2.3.4/error_prone_annotations-2.3.4.jar (14 kB at 22 kB/s)&#xA;Progress (2): 8.8 kB | 4.1/500 kB&#xD;Progress (2): 8.8 kB | 7.7/500 kB&#xD;Progress (2): 8.8 kB | 12/500 kB &#xD;Progress (2): 8.8 kB | 16/500 kB&#xD;Progress (2): 8.8 kB | 20/500 kB&#xD;Progress (2): 8.8 kB | 24/500 kB&#xD;Progress (2): 8.8 kB | 28/500 kB&#xD;Progress (2): 8.8 kB | 32/500 kB&#xD;Progress (2): 8.8 kB | 36/500 kB&#xD;Progress (2): 8.8 kB | 40/500 kB&#xD;Progress (2): 8.8 kB | 45/500 kB&#xD;Progress (2): 8.8 kB | 49/500 kB&#xD;Progress (2): 8.8 kB | 53/500 kB&#xD;Progress (2): 8.8 kB | 57/500 kB&#xD;Progress (2): 8.8 kB | 61/500 kB&#xD;Progress (2): 8.8 kB | 65/500 kB&#xD;Progress (2): 8.8 kB | 69/500 kB&#xD;Progress (2): 8.8 kB | 73/500 kB&#xD;Progress (2): 8.8 kB | 77/500 kB&#xD;Progress (2): 8.8 kB | 81/500 kB&#xD;Progress (2): 8.8 kB | 86/500 kB&#xD;Progress (2): 8.8 kB | 90/500 kB&#xD;Progress (2): 8.8 kB | 94/500 kB&#xD;Progress (2): 8.8 kB | 98/500 kB&#xD;Progress (2): 8.8 kB | 102/500 kB&#xD;Progress (2): 8.8 kB | 106/500 kB&#xD;Progress (2): 8.8 kB | 110/500 kB&#xD;Progress (2): 8.8 kB | 114/500 kB&#xD;Progress (2): 8.8 kB | 118/500 kB&#xD;Progress (2): 8.8 kB | 122/500 kB&#xD;Progress (2): 8.8 kB | 126/500 kB&#xD;Progress (2): 8.8 kB | 131/500 kB&#xD;Progress (2): 8.8 kB | 135/500 kB&#xD;Progress (2): 8.8 kB | 139/500 kB&#xD;Progress (2): 8.8 kB | 143/500 kB&#xD;Progress (2): 8.8 kB | 147/500 kB&#xD;Progress (2): 8.8 kB | 151/500 kB&#xD;Progress (2): 8.8 kB | 155/500 kB&#xD;Progress (2): 8.8 kB | 159/500 kB&#xD;Progress (2): 8.8 kB | 163/500 kB&#xD;Progress (2): 8.8 kB | 167/500 kB&#xD;Progress (2): 8.8 kB | 172/500 kB&#xD;Progress (2): 8.8 kB | 176/500 kB&#xD;Progress (2): 8.8 kB | 180/500 kB&#xD;Progress (2): 8.8 kB | 184/500 kB&#xD;Progress (2): 8.8 kB | 188/500 kB&#xD;Progress (2): 8.8 kB | 192/500 kB&#xD;Progress (2): 8.8 kB | 196/500 kB&#xD;Progress (2): 8.8 kB | 200/500 kB&#xD;Progress (2): 8.8 kB | 204/500 kB&#xD;Progress (2): 8.8 kB | 208/500 kB&#xD;Progress (2): 8.8 kB | 212/500 kB&#xD;Progress (2): 8.8 kB | 216/500 kB&#xD;Progress (2): 8.8 kB | 220/500 kB&#xD;Progress (2): 8.8 kB | 224/500 kB&#xD;Progress (2): 8.8 kB | 228/500 kB&#xD;Progress (2): 8.8 kB | 232/500 kB&#xD;Progress (2): 8.8 kB | 236/500 kB&#xD;Progress (2): 8.8 kB | 241/500 kB&#xD;Progress (2): 8.8 kB | 245/500 kB&#xD;                                 &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/com/google/j2objc/j2objc-annotations/1.3/j2objc-annotations-1.3.jar (8.8 kB at 13 kB/s)&#xA;Progress (1): 249/500 kB&#xD;Progress (1): 253/500 kB&#xD;Progress (1): 257/500 kB&#xD;Progress (1): 261/500 kB&#xD;Progress (1): 265/500 kB&#xD;Progress (1): 269/500 kB&#xD;Progress (1): 273/500 kB&#xD;Progress (1): 277/500 kB&#xD;Progress (1): 282/500 kB&#xD;Progress (1): 286/500 kB&#xD;Progress (1): 290/500 kB&#xD;Progress (1): 294/500 kB&#xD;Progress (1): 298/500 kB&#xD;Progress (1): 302/500 kB&#xD;Progress (1): 306/500 kB&#xD;Progress (1): 310/500 kB&#xD;Progress (1): 314/500 kB&#xD;Progress (1): 318/500 kB&#xD;Progress (1): 322/500 kB&#xD;Progress (1): 327/500 kB&#xD;Progress (1): 331/500 kB&#xD;Progress (1): 335/500 kB&#xD;Progress (1): 339/500 kB&#xD;Progress (1): 343/500 kB&#xD;Progress (1): 347/500 kB&#xD;Progress (1): 351/500 kB&#xD;Progress (1): 355/500 kB&#xD;Progress (1): 359/500 kB&#xD;Progress (1): 363/500 kB&#xD;Progress (1): 367/500 kB&#xD;Progress (1): 371/500 kB&#xD;Progress (1): 376/500 kB&#xD;Progress (1): 380/500 kB&#xD;Progress (1): 384/500 kB&#xD;Progress (1): 388/500 kB&#xD;Progress (1): 392/500 kB&#xD;Progress (1): 396/500 kB&#xD;Progress (1): 400/500 kB&#xD;Progress (1): 404/500 kB&#xD;Progress (1): 408/500 kB&#xD;Progress (1): 412/500 kB&#xD;Progress (1): 416/500 kB&#xD;Progress (1): 420/500 kB&#xD;Progress (1): 424/500 kB&#xD;Progress (1): 428/500 kB&#xD;Progress (1): 432/500 kB&#xD;Progress (1): 436/500 kB&#xD;Progress (1): 440/500 kB&#xD;Progress (1): 445/500 kB&#xD;Progress (1): 449/500 kB&#xD;Progress (1): 453/500 kB&#xD;Progress (1): 457/500 kB&#xD;Progress (1): 461/500 kB&#xD;Progress (1): 465/500 kB&#xD;Progress (1): 469/500 kB&#xD;Progress (1): 473/500 kB&#xD;Progress (1): 477/500 kB&#xD;Progress (1): 481/500 kB&#xD;Progress (1): 486/500 kB&#xD;Progress (1): 490/500 kB&#xD;Progress (1): 494/500 kB&#xD;Progress (1): 498/500 kB&#xD;Progress (1): 500 kB    &#xD;                    &#xD;Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/commons/commons-lang3/3.7/commons-lang3-3.7.jar (500 kB at 720 kB/s)&#xA;[INFO] Including io.github.stuartwdouglas.hacbs-test.simple:simple-jdk17:jar:0.1.2 in the shaded jar.&#xA;[INFO] Including io.github.stuartwdouglas.hacbs-test.shaded:shaded-jdk11:jar:1.9 in the shaded jar.&#xA;[INFO] Including io.github.stuartwdouglas.hacbs-test.simple:simple-jdk8:jar:1.2.4 in the shaded jar.&#xA;[INFO] Including io.github.stuartwdouglas.hacbs-test.gradle:hacbs-test-simple-gradle-jdk8:jar:1.1 in the shaded jar.&#xA;[WARNING] hacbs-test-simple-gradle-jdk8-1.1.jar, hacbs-test.jar, shaded-jdk11-1.9.jar, simple-jdk17-0.1.2.jar, simple-jdk8-1.2.4.jar define 1 overlapping resource: &#xA;[WARNING]   - META-INF/MANIFEST.MF&#xA;[WARNING] shaded-jdk11-1.9.jar, simple-jdk8-1.2.4.jar define 3 overlapping classes and resources: &#xA;[WARNING]   - META-INF/maven/io.github.stuartwdouglas.hacbs-test.simple/simple-jdk8/pom.properties&#xA;[WARNING]   - META-INF/maven/io.github.stuartwdouglas.hacbs-test.simple/simple-jdk8/pom.xml&#xA;[WARNING]   - io.github.stuartwdouglas.hacbstest.simple.simplejdk8.Placeholder&#xA;[WARNING] maven-shade-plugin has detected that some class files are&#xA;[WARNING] present in two or more JARs. When this happens, only one&#xA;[WARNING] single version of the class is copied to the uber jar.&#xA;[WARNING] Usually this is not harmful and you can skip these warnings,&#xA;[WARNING] otherwise try to manually exclude artifacts based on&#xA;[WARNING] mvn dependency:tree -Ddetail=true and the above output.&#xA;[WARNING] See http://maven.apache.org/plugins/maven-shade-plugin/&#xA;[INFO] Replacing original artifact with shaded artifact.&#xA;[INFO] Replacing /work/target/hacbs-test.jar with /work/target/simple-java-project-1.0-SNAPSHOT-shaded.jar&#xA;[INFO] ------------------------------------------------------------------------&#xA;[INFO] BUILD SUCCESS&#xA;[INFO] ------------------------------------------------------------------------&#xA;[INFO] Total time:  25.880 s&#xA;[INFO] Finished at: 2026-04-22T13:53:29Z&#xA;[INFO] ------------------------------------------------------------------------&#xA;[2/2] STEP 1/10: FROM registry.access.redhat.com/ubi8/openjdk-17-runtime:1.23&#xA;[2/2] STEP 2/10: USER 185&#xA;[2/2] STEP 3/10: WORKDIR /work/&#xA;[2/2] STEP 4/10: COPY --from=builder /work/target/hacbs-test.jar /deployments&#xA;[2/2] STEP 5/10: EXPOSE 8081&#xA;[2/2] STEP 6/10: ENV AB_JOLOKIA_OFF=&#34;&#34;&#xA;[2/2] STEP 7/10: ENV JAVA_APP_JAR=&#34;/deployments/hacbs-test.jar&#34;&#xA;[2/2] STEP 8/10: COPY labels.json /usr/share/buildinfo/labels.json&#xA;[2/2] STEP 9/10: COPY labels.json /root/buildinfo/labels.json&#xA;[2/2] STEP 10/10: LABEL &#34;architecture&#34;=&#34;x86_64&#34; &#34;vcs-type&#34;=&#34;git&#34; &#34;vcs-ref&#34;=&#34;ed3328a539acc00b4d626fb0525fc3656cfad118&#34; &#34;org.opencontainers.image.revision&#34;=&#34;ed3328a539acc00b4d626fb0525fc3656cfad118&#34; &#34;org.opencontainers.image.source&#34;=&#34;https://github.com/redhat-appstudio-qe/konflux-test-integration&#34; &#34;quay.expires-after&#34;=&#34;6h&#34; &#34;build-date&#34;=&#34;2026-04-22T13:52:19Z&#34; &#34;org.opencontainers.image.created&#34;=&#34;2026-04-22T13:52:19Z&#34;&#xA;[2/2] COMMIT quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;--&gt; 66fce7c70ec0&#xA;Successfully tagged quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;66fce7c70ec0ace2af305ca5355de3cdaa86ff02b14a7ff6e6949f9aa9ad84e2&#xA;[2026-04-22T13:53:31,072874540+00:00] Unsetting proxy&#xA;[2026-04-22T13:53:31,074162258+00:00] Add metadata&#xA;Recording base image digests used&#xA;registry.access.redhat.com/ubi8/openjdk-17:1.23 registry.access.redhat.com/ubi8/openjdk-17:1.23@sha256:402a4439d4685294ff33f924f757e962428a8cb41e1f69cd7336b67844dd6f8f&#xA;registry.access.redhat.com/ubi8/openjdk-17-runtime:1.23 registry.access.redhat.com/ubi8/openjdk-17-runtime:1.23@sha256:151f4f781ee4280a6b9f0a8ae75caf70723d2c9c8c940cf193a456873064647e&#xA;Getting image source signatures&#xA;Copying blob sha256:8dbf1597f50ec23e567040c4101c9212913f074c6f2f24a143d31be34b67d6e5&#xA;Copying blob sha256:82e94a78e5b3f6e090eb99ece36c5d39a3329a736933c800cc56623bff3e77e9&#xA;Copying blob sha256:69fb55955bb195dd1f75faa6d15da2a9617eb7bed59320c598bfa1d74d874213&#xA;Copying config sha256:66fce7c70ec0ace2af305ca5355de3cdaa86ff02b14a7ff6e6949f9aa9ad84e2&#xA;Writing manifest to image destination&#xA;[2026-04-22T13:53:32,384449981+00:00] End build&#xA;&#xA;pod: test-component-pac-jfjqoi-ob4259b147a08930b3126dc25f096f4e6-pod | container step-push: &#xA;[2026-04-22T13:53:32,679823213+00:00] Update CA trust&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;[2026-04-22T13:53:34,809816533+00:00] Convert image&#xA;[2026-04-22T13:53:34,810923449+00:00] Push image with unique tag&#xA;Pushing to quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:test-component-pac-jfjqoi-on-pull-request-pdc9m-build-container&#xA;[retry] executing: buildah push --format=docker --retry 3 --tls-verify=true quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118 docker://quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:test-component-pac-jfjqoi-on-pull-request-pdc9m-build-container&#xA;Getting image source signatures&#xA;Copying blob sha256:8dbf1597f50ec23e567040c4101c9212913f074c6f2f24a143d31be34b67d6e5&#xA;Copying blob sha256:69fb55955bb195dd1f75faa6d15da2a9617eb7bed59320c598bfa1d74d874213&#xA;Copying blob sha256:82e94a78e5b3f6e090eb99ece36c5d39a3329a736933c800cc56623bff3e77e9&#xA;Copying config sha256:66fce7c70ec0ace2af305ca5355de3cdaa86ff02b14a7ff6e6949f9aa9ad84e2&#xA;Writing manifest to image destination&#xA;[2026-04-22T13:53:43,222501867+00:00] Push image with git revision&#xA;Pushing to quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;[retry] executing: buildah push --format=docker --retry 3 --tls-verify=true --digestfile /workspace/source/image-digest quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118 docker://quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;Getting image source signatures&#xA;Copying blob sha256:8dbf1597f50ec23e567040c4101c9212913f074c6f2f24a143d31be34b67d6e5&#xA;Copying blob sha256:82e94a78e5b3f6e090eb99ece36c5d39a3329a736933c800cc56623bff3e77e9&#xA;Copying blob sha256:69fb55955bb195dd1f75faa6d15da2a9617eb7bed59320c598bfa1d74d874213&#xA;Copying config sha256:66fce7c70ec0ace2af305ca5355de3cdaa86ff02b14a7ff6e6949f9aa9ad84e2&#xA;Writing manifest to image destination&#xA;sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;[retry] executing: kubectl get configmap cluster-config -n konflux-info -o json&#xA;Keyless signing is disabled (none of rekorInternalUrl, fulcioInternalUrl, defaultOIDCIssuer, tufInternalUrl are configured in the konflux-info/cluster-config configmap)&#xA;[2026-04-22T13:53:44,093066717+00:00] End push&#xA;&#xA;pod: test-component-pac-jfjqoi-ob4259b147a08930b3126dc25f096f4e6-pod | container step-sbom-syft-generate: &#xA;[2026-04-22T13:53:44,985037256+00:00] Generate SBOM&#xA;Running syft on the image&#xA;Running syft on the source code&#xA;[0000]  WARN no explicit name and version provided for directory source, deriving artifact ID from the given path (which is not ideal)&#xA;[2026-04-22T13:53:53,128656003+00:00] End sbom-syft-generate&#xA;&#xA;pod: test-component-pac-jfjqoi-ob4259b147a08930b3126dc25f096f4e6-pod | container step-prepare-sboms: &#xA;[2026-04-22T13:53:53,333684679+00:00] Prepare SBOM&#xA;[2026-04-22T13:53:53,337522687+00:00] Generate SBOM with mobster&#xA;Skipping SBOM validation&#xA;2026-04-22 13:53:54,465 [INFO] mobster.log: Logging level set to 20&#xA;2026-04-22 13:53:54,568 [INFO] mobster.oci: Fetching manifest for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:151f4f781ee4280a6b9f0a8ae75caf70723d2c9c8c940cf193a456873064647e&#xA;2026-04-22 13:53:55,320 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type spdxjson failed for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463 with output b&#34;Error: no attestations with predicate type &#39;https://spdx.dev/Document&#39; found\nerror during command execution: no attestations with predicate type &#39;https://spdx.dev/Document&#39; found\n&#34;&#xA;2026-04-22 13:53:55,507 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type cyclonedx failed for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463 with output b&#34;Error: no attestations with predicate type &#39;https://cyclonedx.org/bom&#39; found\nerror during command execution: no attestations with predicate type &#39;https://cyclonedx.org/bom&#39; found\n&#34;&#xA;2026-04-22 13:53:55,975 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type spdxjson failed for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463 with output b&#34;Error: no attestations with predicate type &#39;https://spdx.dev/Document&#39; found\nerror during command execution: no attestations with predicate type &#39;https://spdx.dev/Document&#39; found\n&#34;&#xA;2026-04-22 13:53:56,183 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type cyclonedx failed for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463 with output b&#34;Error: no attestations with predicate type &#39;https://cyclonedx.org/bom&#39; found\nerror during command execution: no attestations with predicate type &#39;https://cyclonedx.org/bom&#39; found\n&#34;&#xA;2026-04-22 13:53:56,587 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type spdxjson failed for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463 with output b&#34;Error: no attestations with predicate type &#39;https://spdx.dev/Document&#39; found\nerror during command execution: no attestations with predicate type &#39;https://spdx.dev/Document&#39; found\n&#34;&#xA;2026-04-22 13:53:56,848 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type cyclonedx failed for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463 with output b&#34;Error: no attestations with predicate type &#39;https://cyclonedx.org/bom&#39; found\nerror during command execution: no attestations with predicate type &#39;https://cyclonedx.org/bom&#39; found\n&#34;&#xA;2026-04-22 13:53:57,274 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type spdxjson failed for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463 with output b&#34;Error: no attestations with predicate type &#39;https://spdx.dev/Document&#39; found\nerror during command execution: no attestations with predicate type &#39;https://spdx.dev/Document&#39; found\n&#34;&#xA;2026-04-22 13:53:57,574 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type cyclonedx failed for registry.access.redhat.com/ubi8/openjdk-17-runtime@sha256:0b1cabb75e483f0475292ba662c2b361a2979d0dbfbeb7228d1e79696f675463 with output b&#34;Error: no attestations with predicate type &#39;https://cyclonedx.org/bom&#39; found\nerror during command execution: no attestations with predicate type &#39;https://cyclonedx.org/bom&#39; found\n&#34;&#xA;2026-04-22 13:53:57,575 [INFO] mobster.cmd.generate.oci_image.contextual_sbom.contextualize: Contextual mechanism won&#39;t be used, there is no parent image SBOM.&#xA;2026-04-22 13:53:57,575 [INFO] mobster.cmd.generate.oci_image: Contextual SBOM workflow finished successfully.&#xA;2026-04-22 13:53:57,575 [INFO] mobster.log: Contextual workflow completed in 3.03s&#xA;2026-04-22 13:53:57,608 [INFO] mobster.main: Exiting with code 0.&#xA;[2026-04-22T13:53:57,675287165+00:00] End prepare-sboms&#xA;&#xA;pod: test-component-pac-jfjqoi-ob4259b147a08930b3126dc25f096f4e6-pod | container step-upload-sbom: &#xA;[2026-04-22T13:53:58,420273132+00:00] Upload SBOM&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;Using token for quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi&#xA;Pushing sbom to registry&#xA;[retry] executing: cosign attach sbom --sbom sbom.json --type spdx quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118@sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138&#xA;WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations.&#xA;WARNING: Attaching SBOMs this way does not sign them. To sign them, use &#39;cosign attest --predicate sbom.json --key &lt;key path&gt;&#39;.&#xA;Uploading SBOM file for [quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi@sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138] to [quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:sha256-01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138.sbom] with mediaType [text/spdx+json].&#xA;&#xA;quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi@sha256:99f25f735defe4a981b505f9a6ed0e1a24e03d72b99557ddf071930635848ca8&#xA;[2026-04-22T13:54:02,057519078+00:00] End upload-sbom&#xA;&#xA; pod: test-component-pac-jfjqoi-ob91cdd20e20be95d22114e74c7e25b68-pod | init container: prepare&#xA;2026/04/22 13:54:53 Entrypoint initialization&#xA;&#xA; pod: test-component-pac-jfjqoi-ob91cdd20e20be95d22114e74c7e25b68-pod | init container: place-scripts&#xA;2026/04/22 13:54:54 Decoded script /tekton/scripts/script-0-q4mpv&#xA;2026/04/22 13:54:54 Decoded script /tekton/scripts/script-1-8sn49&#xA;&#xA; pod: test-component-pac-jfjqoi-ob91cdd20e20be95d22114e74c7e25b68-pod | init container: working-dir-initializer&#xA;&#xA;pod: test-component-pac-jfjqoi-ob91cdd20e20be95d22114e74c7e25b68-pod | container step-sast-snyk-check: &#xA;INFO: The PROJECT_NAME used is: test-component-pac-jfjqoi&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;{&#34;result&#34;:&#34;SKIPPED&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:55:01+00:00&#34;,&#34;note&#34;:&#34;Task sast-snyk-check skipped: If you wish to use the Snyk code SAST task, please create a secret name snyk-secret with the key &#39;snyk_token&#39; containing the Snyk token by following the steps given [here](https://konflux-ci.dev/docs/testing/build/snyk/)&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;&#xA;pod: test-component-pac-jfjqoi-ob91cdd20e20be95d22114e74c7e25b68-pod | container step-upload: &#xA;No sast_snyk_check_out.sarif exists. Skipping upload.&#xA;No excluded-findings.json exists. Skipping upload.&#xA;&#xA; pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-apply-tags-pod | init container: prepare&#xA;2026/04/22 13:54:39 Entrypoint initialization&#xA;&#xA;pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-apply-tags-pod | container step-apply-additional-tags: &#xA;time=&#34;2026-04-22T13:54:41Z&#34; level=info msg=&#34;[param] image-url: quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#34;&#xA;time=&#34;2026-04-22T13:54:41Z&#34; level=info msg=&#34;[param] digest: sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138&#34;&#xA;time=&#34;2026-04-22T13:54:41Z&#34; level=info msg=&#34;[param] tags-from-image-label: konflux.additional-tags&#34;&#xA;time=&#34;2026-04-22T13:54:42Z&#34; level=warning msg=&#34;No tags given in &#39;konflux.additional-tags&#39; image label&#34;&#xA;{&#34;tags&#34;:[]}&#xA; pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clair-scan-pod | init container: prepare&#xA;2026/04/22 13:54:38 Entrypoint initialization&#xA;&#xA; pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clair-scan-pod | init container: place-scripts&#xA;2026/04/22 13:54:38 Decoded script /tekton/scripts/script-0-9t7xz&#xA;2026/04/22 13:54:38 Decoded script /tekton/scripts/script-1-dtk5x&#xA;2026/04/22 13:54:38 Decoded script /tekton/scripts/script-2-gcsvs&#xA;2026/04/22 13:54:38 Decoded script /tekton/scripts/script-3-v6gm8&#xA;&#xA;pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clair-scan-pod | container step-get-image-manifests: &#xA;&#xA;pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clair-scan-pod | container step-get-vulnerabilities: &#xA;&#xA;pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clair-scan-pod | container step-oci-attach-report: &#xA;&#xA;pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clair-scan-pod | container step-conftest-vulnerabilities: &#xA;&#xA; pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clamav-scan-pod | init container: prepare&#xA;2026/04/22 13:54:38 Entrypoint initialization&#xA;&#xA; pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clamav-scan-pod | init container: place-scripts&#xA;2026/04/22 13:54:38 Decoded script /tekton/scripts/script-0-xsr7h&#xA;2026/04/22 13:54:38 Decoded script /tekton/scripts/script-1-xtbqr&#xA;&#xA;pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clamav-scan-pod | container step-extract-and-scan-image: &#xA;Starting clamd ...&#xA;clamd is ready!&#xA;Detecting artifact type for quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi@sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138.&#xA;Detected container image. Processing image manifests.&#xA;Running &#34;oc image extract&#34; on image of arch amd64&#xA;Scanning image for arch amd64. This operation may take a while.&#xA;&#xA;----------- SCAN SUMMARY -----------&#xA;Infected files: 0&#xA;Time: 54.476 sec (0 m 54 s)&#xA;Start Date: 2026:04:22 13:54:59&#xA;End Date:   2026:04:22 13:55:54&#xA;Executed-on: Scan was executed on clamsdcan version - ClamAV 1.4.3/27979/Wed Apr 22 06:26:01 2026 Database version: 27979&#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/work/logs/clamscan-result-log-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 2&#xA;&#x9;}&#xA;]&#xA;{&#34;timestamp&#34;:&#34;1776866154&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;timestamp&#34;:&#34;1776866154&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;timestamp&#34;:&#34;1776866154&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#34;, &#34;digests&#34;: [&#34;sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138&#34;]}}&#xA;&#xA;pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-clamav-scan-pod | container step-upload: &#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi&#xA;Attaching to quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118&#xA;Executing: oras attach --no-tty --registry-config /home/oras/auth.json --artifact-type application/vnd.clamav quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118@sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138 clamscan-result-amd64.log:text/vnd.clamav clamscan-ec-test-amd64.json:application/vnd.konflux.test_output+json&#xA;Preparing clamscan-result-amd64.log&#xA;Preparing clamscan-ec-test-amd64.json&#xA;Exists    44136fa355b3 application/vnd.oci.empty.v1+json&#xA;Uploading b2062823b79a clamscan-result-amd64.log&#xA;Uploading 0b4ab37e6939 clamscan-ec-test-amd64.json&#xA;Uploaded  0b4ab37e6939 clamscan-ec-test-amd64.json&#xA;Uploaded  b2062823b79a clamscan-result-amd64.log&#xA;Uploading a9675cb8488c application/vnd.oci.image.manifest.v1+json&#xA;Uploaded  a9675cb8488c application/vnd.oci.image.manifest.v1+json&#xA;Attached to [registry] quay.io/redhat-appstudio-qe/integration1-fgqi/test-component-pac-jfjqoi:on-pr-ed3328a539acc00b4d626fb0525fc3656cfad118@sha256:01c2be7821974e16be449d1c0be39656a2e26ce1599ccda98c402c99e732c138&#xA;Digest: sha256:a9675cb8488ce7b90f4e0af7ff8dad939c30aeb0c9e20a808c59eb46a4b12ece&#xA;&#xA; pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-init-pod | init container: prepare&#xA;2026/04/22 13:50:54 Entrypoint initialization&#xA;&#xA;pod: test-component-pac-jfjqoi-on-pull-request-pdc9m-init-pod | container step-init: &#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-22T13:51:05Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;New PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 found after retrigger for component integration1-fgqi/test-component-pac-jfjqoi&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 found for Component integration1-fgqi/test-component-pac-jfjqoi&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Running&#xA;PipelineRun test-component-pac-jfjqoi-on-pull-request-jnvf5 reason: Completed&#xA;&lt; Exit [It] waits for build PipelineRun to succeed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:101 @ 04/22/26 14:00:30.162 (9m33.269s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.162&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.162 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when a new Component is created should have a related PaC init PR created [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.276976186">
              <system-err>&gt; Enter [It] should have a related PaC init PR created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:107 @ 04/22/26 14:00:30.164&#xA;&lt; Exit [It] should have a related PaC init PR created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:107 @ 04/22/26 14:00:30.44 (277ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.44&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.44 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the BuildPipelineRun have the annotation of chains signed [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.181443397">
              <system-err>&gt; Enter [It] checks if the BuildPipelineRun have the annotation of chains signed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:128 @ 04/22/26 14:00:30.441&#xA;&lt; Exit [It] checks if the BuildPipelineRun have the annotation of chains signed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:128 @ 04/22/26 14:00:30.622 (181ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.622&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.622 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the Snapshot is created [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.024753845">
              <system-err>&gt; Enter [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:132 @ 04/22/26 14:00:30.623&#xA;&lt; Exit [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:132 @ 04/22/26 14:00:30.647 (24ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.647&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.647 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the Build PipelineRun got annotated with Snapshot name [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.154865275">
              <system-err>&gt; Enter [It] checks if the Build PipelineRun got annotated with Snapshot name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:137 @ 04/22/26 14:00:30.648&#xA;&lt; Exit [It] checks if the Build PipelineRun got annotated with Snapshot name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:137 @ 04/22/26 14:00:30.802 (154ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.803&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.803 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded verifies that the finalizer has been removed from the build pipelinerun [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.071217183">
              <system-err>&gt; Enter [It] verifies that the finalizer has been removed from the build pipelinerun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:141 @ 04/22/26 14:00:30.803&#xA;&lt; Exit [It] verifies that the finalizer has been removed from the build pipelinerun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:141 @ 04/22/26 14:00:30.874 (71ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.874&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:30.874 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if all of the integrationPipelineRuns passed [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="passed" time="0.137407327">
              <system-err>&gt; Enter [It] checks if all of the integrationPipelineRuns passed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:154 @ 04/22/26 14:00:30.875&#xA;Integration test scenario my-integration-test-zltt is found&#xA;PipelineRun my-integration-test-zltt-c92xm reason: Succeeded&#xA;&lt; Exit [It] checks if all of the integrationPipelineRuns passed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:154 @ 04/22/26 14:00:31.012 (137ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.012&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.012 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the passed status of integration test is reported in the Snapshot [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.032799296">
              <system-err>&gt; Enter [It] checks if the passed status of integration test is reported in the Snapshot - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:158 @ 04/22/26 14:00:31.012&#xA;&lt; Exit [It] checks if the passed status of integration test is reported in the Snapshot - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:158 @ 04/22/26 14:00:31.045 (32ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.045&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.045 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the skipped integration test is absent from the Snapshot&#39;s status annotation [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.073210593">
              <system-err>&gt; Enter [It] checks if the skipped integration test is absent from the Snapshot&#39;s status annotation - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:173 @ 04/22/26 14:00:31.046&#xA;&lt; Exit [It] checks if the skipped integration test is absent from the Snapshot&#39;s status annotation - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:173 @ 04/22/26 14:00:31.119 (73ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.119&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.119 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when the build pipelineRun run succeeded checks if the finalizer was removed from all of the related Integration pipelineRuns [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.278419784">
              <system-err>&gt; Enter [It] checks if the finalizer was removed from all of the related Integration pipelineRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:183 @ 04/22/26 14:00:31.119&#xA;Integration test scenario my-integration-test-zltt is found&#xA;&lt; Exit [It] checks if the finalizer was removed from all of the related Integration pipelineRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:183 @ 04/22/26 14:00:31.397 (278ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.397&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.397 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service creates a ReleasePlan [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.51836744">
              <system-err>&gt; Enter [It] creates a ReleasePlan - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:188 @ 04/22/26 14:00:31.398&#xA;IntegrationTestScenario my-integration-test-zltt is found&#xA;IntegrationTestScenario skipped-its is found&#xA;&lt; Exit [It] creates a ReleasePlan - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:188 @ 04/22/26 14:00:31.916 (518ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.916&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:31.916 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service creates an snapshot of push event [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.269269221">
              <system-err>&gt; Enter [It] creates an snapshot of push event - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:198 @ 04/22/26 14:00:31.917&#xA;&lt; Exit [It] creates an snapshot of push event - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:198 @ 04/22/26 14:00:32.185 (269ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:32.186&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:32.186 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when An snapshot of push event is created checks if the global candidate is updated after push event [integration-service]" classname="Red Hat App Studio E2E tests" status="passed" time="0.027115142">
              <system-err>&gt; Enter [It] checks if the global candidate is updated after push event - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:205 @ 04/22/26 14:00:32.187&#xA;&lt; Exit [It] checks if the global candidate is updated after push event - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:205 @ 04/22/26 14:00:32.213 (27ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:32.214&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:00:32.214 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when An snapshot of push event is created checks if all of the integrationPipelineRuns created by push event passed [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="failed" time="60.927201799">
              <failure message="Error when waiting for one of the integration pipelines to finish in integration1-fgqi namespace&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00154a3c0&gt;: &#xA;    error occurred while waiting for Integration PLR (associated with IntegrationTestScenario: my-integration-test-zltt) to get finished in integration1-fgqi namespace. Error: Pipelinerun &#39;my-integration-test-zltt-z2vgw&#39; didn&#39;t succeed&#xA;    &#xA;    {&#xA;        s: &#34;error occurred while waiting for Integration PLR (associated with IntegrationTestScenario: my-integration-test-zltt) to get finished in integration1-fgqi namespace. Error: Pipelinerun &#39;my-integration-test-zltt-z2vgw&#39; didn&#39;t succeed\n&#34;,&#xA;    }" type="failed">[FAILED] Error when waiting for one of the integration pipelines to finish in integration1-fgqi namespace&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00154a3c0&gt;: &#xA;    error occurred while waiting for Integration PLR (associated with IntegrationTestScenario: my-integration-test-zltt) to get finished in integration1-fgqi namespace. Error: Pipelinerun &#39;my-integration-test-zltt-z2vgw&#39; didn&#39;t succeed&#xA;    &#xA;    {&#xA;        s: &#34;error occurred while waiting for Integration PLR (associated with IntegrationTestScenario: my-integration-test-zltt) to get finished in integration1-fgqi namespace. Error: Pipelinerun &#39;my-integration-test-zltt-z2vgw&#39; didn&#39;t succeed\n&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:219 @ 04/22/26 14:01:32.256&#xA;</failure>
              <system-err>&gt; Enter [It] checks if all of the integrationPipelineRuns created by push event passed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:218 @ 04/22/26 14:00:32.214&#xA;Integration test scenario my-integration-test-zltt is found&#xA;PipelineRun has not been created yet for test scenario %s and snapshot %s/%s my-integration-test-zltt integration1-fgqi snapshot-sample-apiz&#xA;PipelineRun my-integration-test-zltt-z2vgw reason: Running&#xA;PipelineRun my-integration-test-zltt-z2vgw reason: Running&#xA;PipelineRun my-integration-test-zltt-z2vgw reason: Failed&#xA;[FAILED] Error when waiting for one of the integration pipelines to finish in integration1-fgqi namespace&#xA;Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc00154a3c0&gt;: &#xA;    error occurred while waiting for Integration PLR (associated with IntegrationTestScenario: my-integration-test-zltt) to get finished in integration1-fgqi namespace. Error: Pipelinerun &#39;my-integration-test-zltt-z2vgw&#39; didn&#39;t succeed&#xA;    &#xA;    {&#xA;        s: &#34;error occurred while waiting for Integration PLR (associated with IntegrationTestScenario: my-integration-test-zltt) to get finished in integration1-fgqi namespace. Error: Pipelinerun &#39;my-integration-test-zltt-z2vgw&#39; didn&#39;t succeed\n&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:219 @ 04/22/26 14:01:32.256&#xA;&lt; Exit [It] checks if all of the integrationPipelineRuns created by push event passed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:218 @ 04/22/26 14:01:32.256 (1m0.042s)&#xA;&gt; Enter [AfterAll] with happy path for general flow of Integration service - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:68 @ 04/22/26 14:01:32.257&#xA;&lt; Exit [AfterAll] with happy path for general flow of Integration service - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:68 @ 04/22/26 14:01:33.03 (773ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:01:33.03&#xA;&lt; Exit [AfterEach] [integration-service-suite Integration Service E2E tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:49 @ 04/22/26 14:01:33.141 (111ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with happy path for general flow of Integration service when An snapshot of push event is created checks if a Release is created successfully [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:222 @ 04/22/26 14:01:33.142&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail triggers a build PipelineRun [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:266 @ 04/22/26 14:01:33.142&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail should have a related PaC init PR created [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:273 @ 04/22/26 14:01:33.142&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the BuildPipelineRun have the annotation of chains signed [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:292 @ 04/22/26 14:01:33.142&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the Snapshot is created [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:296 @ 04/22/26 14:01:33.142&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the Build PipelineRun got annotated with Snapshot name [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:301 @ 04/22/26 14:01:33.143&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if all of the integrationPipelineRuns finished [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:305 @ 04/22/26 14:01:33.143&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the failed status of integration test is reported in the Snapshot [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:309 @ 04/22/26 14:01:33.143&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the skipped integration test is absent from the Snapshot&#39;s status annotation [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:324 @ 04/22/26 14:01:33.143&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if snapshot is marked as failed [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:334 @ 04/22/26 14:01:33.143&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail checks if the finalizer was removed from all of the related Integration pipelineRuns [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:340 @ 04/22/26 14:01:33.144&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail creates a new IntegrationTestScenario [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:344 @ 04/22/26 14:01:33.144&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail updates the Snapshot with the re-run label for the new scenario [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:349 @ 04/22/26 14:01:33.144&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if the new integration pipelineRun started [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:358 @ 04/22/26 14:01:33.145&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if the re-run label was removed from the Snapshot [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:364 @ 04/22/26 14:01:33.145&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if all integration pipelineRuns finished successfully [integration-service, slow]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:378 @ 04/22/26 14:01:33.145&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if the name of the re-triggered pipelinerun is reported in the Snapshot [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:382 @ 04/22/26 14:01:33.146&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot is updated with a re-run label for a given scenario checks if snapshot is still marked as failed [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:399 @ 04/22/26 14:01:33.146&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail creates an snapshot of push event [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:406 @ 04/22/26 14:01:33.146&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Integration Service E2E tests] with an integration test fail when An snapshot of push event is created checks no Release CRs are created [integration-service]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/integration.go:413 @ 04/22/26 14:01:33.146&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created triggers a Build PipelineRun [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="64.382577079">
              <system-err>&gt; Enter [BeforeAll] Gitlab with status reporting of Integration tests in the assosiated merge request - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:45 @ 04/22/26 13:50:09.895&#xA;&lt; Exit [BeforeAll] Gitlab with status reporting of Integration tests in the assosiated merge request - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:45 @ 04/22/26 13:50:13.772 (3.877s)&#xA;&gt; Enter [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:109 @ 04/22/26 13:50:13.772&#xA;Image repository for component test-comp-pac-gitlab-igxorp in namespace gitlab-rep-lobq do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:109 @ 04/22/26 13:50:34.236 (20.464s)&#xA;&gt; Enter [It] triggers a Build PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:130 @ 04/22/26 13:50:34.237&#xA;Build PipelineRun has not been created yet for the component gitlab-rep-lobq/test-comp-pac-gitlab-igxorp&#xA;Build PipelineRun has not been created yet for the component gitlab-rep-lobq/test-comp-pac-gitlab-igxorp&#xA;&lt; Exit [It] triggers a Build PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:130 @ 04/22/26 13:51:14.277 (40.04s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 13:51:14.277&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 13:51:14.277 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created does not contain an annotation with a Snapshot Name [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.000326397">
              <system-err>&gt; Enter [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:144 @ 04/22/26 13:51:14.277&#xA;&lt; Exit [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:144 @ 04/22/26 13:51:14.278 (0s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 13:51:14.278&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 13:51:14.278 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created should lead to build PipelineRun finishing successfully [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="611.307702652">
              <system-err>&gt; Enter [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:148 @ 04/22/26 13:51:14.278&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m found for Component gitlab-rep-lobq/test-comp-pac-gitlab-igxorp&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: ResolvingTaskRef&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m reason: Failed&#xA;attempt 1/3: PipelineRun &#34;test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m&#34; failed: &#xA; pod: test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m-init-pod | init container: prepare&#xA;2026/04/22 13:51:16 Entrypoint initialization&#xA;&#xA;pod: test-comp-pac-gitlab-igxorp-on-pull-request-lbb8m-init-pod | container step-init: &#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-22T13:51:28Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;&#xA; pod: test-comp-pac-gitlab-igxorp60fb35d3220ec4d2e7eeda7d77f3a5fc-pod | init container: prepare&#xA;2026/04/22 13:54:26 Entrypoint initialization&#xA;&#xA;pod: test-comp-pac-gitlab-igxorp60fb35d3220ec4d2e7eeda7d77f3a5fc-pod | container step-apply-additional-tags: &#xA;time=&#34;2026-04-22T13:54:39Z&#34; level=info msg=&#34;[param] image-url: quay.io/redhat-appstudio-qe/gitlab-rep-lobq/test-comp-pac-gitlab-igxorp:on-pr-70cc1ddfcf9cd51615288f9f6cf05c168c0020fd&#34;&#xA;time=&#34;2026-04-22T13:54:39Z&#34; level=info msg=&#34;[param] digest: sha256:1c8c1e36458147ab09c5f56f37d306bc099035e09138d323b899d70a835c7c92&#34;&#xA;time=&#34;2026-04-22T13:54:39Z&#34; level=info msg=&#34;[param] tags-from-image-label: konflux.additional-tags&#34;&#xA;time=&#34;2026-04-22T13:54:40Z&#34; level=warning msg=&#34;No tags given in &#39;konflux.additional-tags&#39; image label&#34;&#xA;{&#34;tags&#34;:[]}&#xA; pod: test-comp-pac-gitlab-igxorpfaf3dc914699e00b644c636367bcea4a-pod | init container: prepare&#xA;2026/04/22 13:54:26 Entrypoint initialization&#xA;&#xA; pod: test-comp-pac-gitlab-igxorpfaf3dc914699e00b644c636367bcea4a-pod | init container: place-scripts&#xA;2026/04/22 13:54:37 Decoded script /tekton/scripts/script-0-k6mzx&#xA;2026/04/22 13:54:37 Decoded script /tekton/scripts/script-1-wszgt&#xA;&#xA;pod: test-comp-pac-gitlab-igxorpfaf3dc914699e00b644c636367bcea4a-pod | container step-extract-and-scan-image: &#xA;Starting clamd ...&#xA;clamd is ready!&#xA;Detecting artifact type for quay.io/redhat-appstudio-qe/gitlab-rep-lobq/test-comp-pac-gitlab-igxorp@sha256:1c8c1e36458147ab09c5f56f37d306bc099035e09138d323b899d70a835c7c92.&#xA;Detected container image. Processing image manifests.&#xA;Running &#34;oc image extract&#34; on image of arch amd64&#xA;Scanning image for arch amd64. This operation may take a while.&#xA;&#xA;----------- SCAN SUMMARY -----------&#xA;Infected files: 0&#xA;Time: 53.914 sec (0 m 53 s)&#xA;Start Date: 2026:04:22 13:55:01&#xA;End Date:   2026:04:22 13:55:55&#xA;Executed-on: Scan was executed on clamsdcan version - ClamAV 1.4.3/27979/Wed Apr 22 06:26:01 2026 Database version: 27979&#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/work/logs/clamscan-result-log-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 2&#xA;&#x9;}&#xA;]&#xA;{&#34;timestamp&#34;:&#34;1776866155&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;timestamp&#34;:&#34;1776866155&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;timestamp&#34;:&#34;1776866155&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/gitlab-rep-lobq/test-comp-pac-gitlab-igxorp:on-pr-70cc1ddfcf9cd51615288f9f6cf05c168c0020fd&#34;, &#34;digests&#34;: [&#34;sha256:1c8c1e36458147ab09c5f56f37d306bc099035e09138d323b899d70a835c7c92&#34;]}}&#xA;&#xA;pod: test-comp-pac-gitlab-igxorpfaf3dc914699e00b644c636367bcea4a-pod | container step-upload: &#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/gitlab-rep-lobq/test-comp-pac-gitlab-igxorp&#xA;Attaching to quay.io/redhat-appstudio-qe/gitlab-rep-lobq/test-comp-pac-gitlab-igxorp:on-pr-70cc1ddfcf9cd51615288f9f6cf05c168c0020fd&#xA;Executing: oras attach --no-tty --registry-config /home/oras/auth.json --artifact-type application/vnd.clamav quay.io/redhat-appstudio-qe/gitlab-rep-lobq/test-comp-pac-gitlab-igxorp:on-pr-70cc1ddfcf9cd51615288f9f6cf05c168c0020fd@sha256:1c8c1e36458147ab09c5f56f37d306bc099035e09138d323b899d70a835c7c92 clamscan-result-amd64.log:text/vnd.clamav clamscan-ec-test-amd64.json:application/vnd.konflux.test_output+json&#xA;Preparing clamscan-result-amd64.log&#xA;Preparing clamscan-ec-test-amd64.json&#xA;Exists    44136fa355b3 application/vnd.oci.empty.v1+json&#xA;Uploading 22c5aee036be clamscan-result-amd64.log&#xA;Uploading 2bdd9a80e476 clamscan-ec-test-amd64.json&#xA;Uploaded  22c5aee036be clamscan-result-amd64.log&#xA;Uploaded  2bdd9a80e476 clamscan-ec-test-amd64.json&#xA;Uploading 3e57afab184e application/vnd.oci.image.manifest.v1+json&#xA;Uploaded  3e57afab184e application/vnd.oci.image.manifest.v1+json&#xA;Attached to [registry] quay.io/redhat-appstudio-qe/gitlab-rep-lobq/test-comp-pac-gitlab-igxorp:on-pr-70cc1ddfcf9cd51615288f9f6cf05c168c0020fd@sha256:1c8c1e36458147ab09c5f56f37d306bc099035e09138d323b899d70a835c7c92&#xA;Digest: sha256:3e57afab184e23eae0c4b1a34bc6957e9f294f784abc3848e2132181a2f7737f&#xA;New PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 found after retrigger for component gitlab-rep-lobq/test-comp-pac-gitlab-igxorp&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 found for Component gitlab-rep-lobq/test-comp-pac-gitlab-igxorp&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: ResolvingTaskRef&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Running&#xA;PipelineRun test-comp-pac-gitlab-igxorp-on-pull-request-rznw8 reason: Completed&#xA;&lt; Exit [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:148 @ 04/22/26 14:01:25.585 (10m11.307s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:25.586&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:25.586 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created should have a related PaC init MR is created [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="1.143959519">
              <system-err>&gt; Enter [It] should have a related PaC init MR is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:153 @ 04/22/26 14:01:25.586&#xA;&lt; Exit [It] should have a related PaC init MR is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:153 @ 04/22/26 14:01:26.73 (1.144s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:26.73&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:26.73 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully for component  [integration-service, gitlab-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="20.016114948">
              <system-err>&gt; Enter [It] the PipelineRun should eventually finish successfully for component  - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:172 @ 04/22/26 14:01:26.73&#xA;PipelineRun my-integration-test-ojhx-6t57r found for Component gitlab-rep-lobq/test-comp-pac-gitlab-igxorp&#xA;PipelineRun my-integration-test-ojhx-6t57r reason: Running&#xA;PipelineRun my-integration-test-ojhx-6t57r reason: Succeeded&#xA;&lt; Exit [It] the PipelineRun should eventually finish successfully for component  - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:172 @ 04/22/26 14:01:46.746 (20.016s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.746&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.746 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when the PaC build pipelineRun run succeeded checks if the BuildPipelineRun have the annotation of chains signed [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.017479687">
              <system-err>&gt; Enter [It] checks if the BuildPipelineRun have the annotation of chains signed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:179 @ 04/22/26 14:01:46.747&#xA;&lt; Exit [It] checks if the BuildPipelineRun have the annotation of chains signed - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:179 @ 04/22/26 14:01:46.764 (17ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.764&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.764 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when the PaC build pipelineRun run succeeded checks if the Snapshot is created [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.00706602">
              <system-err>&gt; Enter [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:183 @ 04/22/26 14:01:46.765&#xA;&lt; Exit [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:183 @ 04/22/26 14:01:46.772 (7ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.772&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.772 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when the PaC build pipelineRun run succeeded checks if the Build PipelineRun got annotated with Snapshot name [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.017213071">
              <system-err>&gt; Enter [It] checks if the Build PipelineRun got annotated with Snapshot name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:188 @ 04/22/26 14:01:46.772&#xA;&lt; Exit [It] checks if the Build PipelineRun got annotated with Snapshot name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:188 @ 04/22/26 14:01:46.789 (17ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.789&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.789 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when the Snapshot was created should find the Integration Test Scenario PipelineRun [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.006252564">
              <system-err>&gt; Enter [It] should find the Integration Test Scenario PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:194 @ 04/22/26 14:01:46.79&#xA;&lt; Exit [It] should find the Integration Test Scenario PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:194 @ 04/22/26 14:01:46.796 (6ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.796&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.796 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created should eventually complete successfully [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.012227183">
              <system-err>&gt; Enter [It] should eventually complete successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:207 @ 04/22/26 14:01:46.796&#xA;PipelineRun my-integration-test-pkvc-mddwl reason: Succeeded&#xA;PipelineRun my-integration-test-ojhx-6t57r reason: Succeeded&#xA;&lt; Exit [It] should eventually complete successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:207 @ 04/22/26 14:01:46.808 (12ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.808&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:46.808 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it pass [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.191044105">
              <system-err>&gt; Enter [It] validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it pass - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:212 @ 04/22/26 14:01:46.809&#xA;&lt; Exit [It] validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it pass - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:212 @ 04/22/26 14:01:46.999 (191ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:47&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:47 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.38059029">
              <system-err>&gt; Enter [It] eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:229 @ 04/22/26 14:01:47&#xA;&lt; Exit [It] eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:229 @ 04/22/26 14:01:47.38 (380ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:47.381&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:47.381 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it fails [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.178157939">
              <system-err>&gt; Enter [It] validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it fails - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:233 @ 04/22/26 14:01:47.381&#xA;&lt; Exit [It] validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it fails - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:233 @ 04/22/26 14:01:47.559 (178ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:47.559&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:47.559 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created eventually leads to the integration test PipelineRun&#39;s Fail status reported at MR commit status [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.45258162">
              <system-err>&gt; Enter [It] eventually leads to the integration test PipelineRun&#39;s Fail status reported at MR commit status - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:250 @ 04/22/26 14:01:47.56&#xA;&lt; Exit [It] eventually leads to the integration test PipelineRun&#39;s Fail status reported at MR commit status - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:250 @ 04/22/26 14:01:48.012 (452ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:48.012&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:48.012 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created validates at least one MR note contains the final integration test result [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.225869497">
              <system-err>&gt; Enter [It] validates at least one MR note contains the final integration test result - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:254 @ 04/22/26 14:01:48.013&#xA;&lt; Exit [It] validates at least one MR note contains the final integration test result - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:254 @ 04/22/26 14:01:48.238 (226ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:48.238&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:48.238 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created merging the PR should be successful [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="1.6805206620000002">
              <system-err>&gt; Enter [It] merging the PR should be successful - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:278 @ 04/22/26 14:01:48.239&#xA;merged result sha: 7d21df9d38a9058bb05bac345ad0b84ec2193e3a for MR #17401&#xA;&lt; Exit [It] merging the PR should be successful - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:278 @ 04/22/26 14:01:49.919 (1.68s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:49.919&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:49.919 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Integration PipelineRun is created leads to triggering on push PipelineRun [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.012473188">
              <system-err>&gt; Enter [It] leads to triggering on push PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:288 @ 04/22/26 14:01:49.92&#xA;&lt; Exit [It] leads to triggering on push PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:288 @ 04/22/26 14:01:49.932 (12ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:49.932&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:49.932 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR should eventually complete successfully [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.012717353">
              <system-err>&gt; Enter [It] should eventually complete successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:303 @ 04/22/26 14:01:49.933&#xA;PipelineRun my-integration-test-pkvc-mddwl reason: Succeeded&#xA;PipelineRun my-integration-test-ojhx-6t57r reason: Succeeded&#xA;&lt; Exit [It] should eventually complete successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:303 @ 04/22/26 14:01:49.945 (12ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:49.945&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:49.945 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it pass [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.19584991">
              <system-err>&gt; Enter [It] validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it pass - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:308 @ 04/22/26 14:01:49.946&#xA;&lt; Exit [It] validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it pass - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:308 @ 04/22/26 14:01:50.141 (195ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:50.141&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:50.141 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.355261197">
              <system-err>&gt; Enter [It] eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:325 @ 04/22/26 14:01:50.142&#xA;&lt; Exit [It] eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:325 @ 04/22/26 14:01:50.497 (355ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:50.497&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:50.497 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it fails [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="0.238700611">
              <system-err>&gt; Enter [It] validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it fails - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:329 @ 04/22/26 14:01:50.497&#xA;&lt; Exit [It] validates the Integration test scenario PipelineRun is reported to merge request CommitStatus, and it fails - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:329 @ 04/22/26 14:01:50.736 (238ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:50.736&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:50.736 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Gitlab Status Reporting of Integration tests] Gitlab with status reporting of Integration tests in the assosiated merge request when Run integration tests after Merged MR eventually leads to the integration test PipelineRun&#39;s Fail status reported at MR commit status [integration-service, gitlab-status-reporting]" classname="Red Hat App Studio E2E tests" status="passed" time="4.039450618">
              <system-err>&gt; Enter [It] eventually leads to the integration test PipelineRun&#39;s Fail status reported at MR commit status - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:346 @ 04/22/26 14:01:50.737&#xA;&lt; Exit [It] eventually leads to the integration test PipelineRun&#39;s Fail status reported at MR commit status - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:346 @ 04/22/26 14:01:51.082 (346ms)&#xA;&gt; Enter [AfterAll] Gitlab with status reporting of Integration tests in the assosiated merge request - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:94 @ 04/22/26 14:01:51.082&#xA;&lt; Exit [AfterAll] Gitlab with status reporting of Integration tests in the assosiated merge request - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:94 @ 04/22/26 14:01:54.776 (3.693s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:54.776&#xA;&lt; Exit [AfterEach] [integration-service-suite Gitlab Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/gitlab-integration-reporting.go:42 @ 04/22/26 14:01:54.776 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created triggers a Build PipelineRun [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="160.196342862">
              <system-err>&gt; Enter [BeforeAll] Forgejo with status reporting of Integration tests in the associated merge request - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:48 @ 04/22/26 13:50:09.791&#xA;&lt; Exit [BeforeAll] Forgejo with status reporting of Integration tests in the associated merge request - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:48 @ 04/22/26 13:50:18.998 (9.207s)&#xA;&gt; Enter [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:112 @ 04/22/26 13:50:18.998&#xA;Image repository for component test-comp-pac-forgejo-wqnvvd in namespace forgejo-rep-xlpn do not have right state (&#39;&#39; != &#39;ready&#39;) yet but it has status {  { } {&lt;nil&gt;      } []}.&#xA;&lt; Exit [BeforeAll] when a new Component with specified custom branch is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:112 @ 04/22/26 13:52:29.946 (2m10.948s)&#xA;&gt; Enter [It] triggers a Build PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:159 @ 04/22/26 13:52:29.946&#xA;Build PipelineRun has not been created yet for the component forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;&lt; Exit [It] triggers a Build PipelineRun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:159 @ 04/22/26 13:52:49.987 (20.041s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:45 @ 04/22/26 13:52:49.987&#xA;&lt; Exit [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:45 @ 04/22/26 13:52:49.988 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created does not contain an annotation with a Snapshot Name [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="passed" time="0.000340067">
              <system-err>&gt; Enter [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:173 @ 04/22/26 13:52:49.988&#xA;&lt; Exit [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:173 @ 04/22/26 13:52:49.988 (0s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:45 @ 04/22/26 13:52:49.988&#xA;&lt; Exit [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:45 @ 04/22/26 13:52:49.988 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created should lead to build PipelineRun finishing successfully [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="failed" time="1794.334833435">
              <failure message="Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0015450d0&gt;: &#xA;    &#xA;     pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | init container: prepare&#xA;    2026/04/22 14:14:24 Entrypoint initialization&#xA;    &#xA;    pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | container step-init: &#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;    &#xA;    {&#xA;        s: &#34;\n pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | init container: prepare\n2026/04/22 14:14:24 Entrypoint initialization\n\npod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | container step-init: \ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;Using in-cluster config\&#34; logger=KubeClient\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] enable: false\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] http-proxy-result-path: /tekton/results/http-proxy\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] no-proxy-result-path: /tekton/results/no-proxy\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;Cache proxy is disabled in param or in backend\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[result] HTTP PROXY: \&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[result] NO PROXY: \&#34;\n&#34;,&#xA;    }" type="failed">[FAILED] Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0015450d0&gt;: &#xA;    &#xA;     pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | init container: prepare&#xA;    2026/04/22 14:14:24 Entrypoint initialization&#xA;    &#xA;    pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | container step-init: &#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;    &#xA;    {&#xA;        s: &#34;\n pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | init container: prepare\n2026/04/22 14:14:24 Entrypoint initialization\n\npod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | container step-init: \ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;Using in-cluster config\&#34; logger=KubeClient\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] enable: false\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] http-proxy-result-path: /tekton/results/http-proxy\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] no-proxy-result-path: /tekton/results/no-proxy\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;Cache proxy is disabled in param or in backend\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[result] HTTP PROXY: \&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[result] NO PROXY: \&#34;\n&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:179 @ 04/22/26 14:22:44.204&#xA;</failure>
              <system-err>&gt; Enter [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:177 @ 04/22/26 13:52:49.989&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 found for Component forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28 reason: Failed&#xA;attempt 1/3: PipelineRun &#34;test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28&#34; failed: &#xA; pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28-init-pod | init container: prepare&#xA;2026/04/22 13:52:39 Entrypoint initialization&#xA;&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28-init-pod | container step-init: &#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-22T13:52:43Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;&#xA; pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28-tpa-scan-pod | init container: prepare&#xA;2026/04/22 14:01:12 Entrypoint initialization&#xA;&#xA; pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28-tpa-scan-pod | init container: place-scripts&#xA;2026/04/22 14:01:12 Decoded script /tekton/scripts/script-0-z6q99&#xA;2026/04/22 14:01:12 Decoded script /tekton/scripts/script-1-m72jx&#xA;2026/04/22 14:01:12 Decoded script /tekton/scripts/script-2-gdkqw&#xA;&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28-tpa-scan-pod | container step-get-vulnerabilities: &#xA;Inspecting raw image manifest quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd@sha256:3256c4ec347b39c20f504484f30eefb1130437a2d703e8e4d257cf3367938d87.&#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations.&#xA;WARNING: Downloading SBOMs this way does not ensure its authenticity. If you want to ensure a tamper-proof SBOM, download it using &#39;cosign download attestation &lt;image uri&gt;&#39;.&#xA;Found SBOM of media type: text/spdx+json&#xA;Running TPA scan on amd64 image manifest...&#xA;  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current&#xA;                                 Dload  Upload   Total   Spent    Left  Speed&#xA;&#xD;  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0&#xD;100  360k    0     0  100  360k      0  1679k --:--:-- --:--:-- --:--:-- 1671k{&#xA;  &#34;scanned&#34; : {&#xA;    &#34;total&#34; : 152,&#xA;    &#34;direct&#34; : 25,&#xA;    &#34;transitive&#34; : 127&#xA;  },&#xA;  &#34;providers&#34; : {&#xA;    &#34;rhtpa&#34; : {&#xA;      &#34;status&#34; : {&#xA;        &#34;ok&#34; : true,&#xA;        &#34;name&#34; : &#34;rhtpa&#34;,&#xA;        &#34;code&#34; : 200,&#xA;        &#34;message&#34; : &#34;OK&#34;,&#xA;        &#34;warnings&#34; : {&#xA;          &#34;pkg:maven/io.github.stuartwdouglas.hacbstest.Main/hacbs-test&#34; : [ &#34;Unable to process: missing version component&#34; ]&#xA;        }&#xA;      },&#xA;      &#34;sources&#34; : {&#xA;        &#34;osv-github&#34; : {&#xA;          &#34;summary&#34; : {&#xA;            &#34;direct&#34; : 2,&#xA;            &#34;transitive&#34; : 0,&#xA;            &#34;total&#34; : 2,&#xA;            &#34;dependencies&#34; : 1,&#xA;            &#34;critical&#34; : 0,&#xA;            &#34;high&#34; : 2,&#xA;            &#34;medium&#34; : 0,&#xA;            &#34;low&#34; : 0,&#xA;            &#34;remediations&#34; : 0,&#xA;            &#34;recommendations&#34; : 0,&#xA;            &#34;unscanned&#34; : 0&#xA;          },&#xA;          &#34;dependencies&#34; : [ {&#xA;            &#34;ref&#34; : &#34;pkg:pypi/setuptools@39.2.0&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          } ]&#xA;        },&#xA;        &#34;redhat-csaf&#34; : {&#xA;          &#34;summary&#34; : {&#xA;            &#34;direct&#34; : 50,&#xA;            &#34;transitive&#34; : 345,&#xA;            &#34;total&#34; : 395,&#xA;            &#34;dependencies&#34; : 57,&#xA;            &#34;critical&#34; : 7,&#xA;            &#34;high&#34; : 133,&#xA;            &#34;medium&#34; : 236,&#xA;            &#34;low&#34; : 19,&#xA;            &#34;remediations&#34; : 0,&#xA;            &#34;recommendations&#34; : 0,&#xA;            &#34;unscanned&#34; : 0&#xA;          },&#xA;          &#34;dependencies&#34; : [ {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;              &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;              &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;              &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;              &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;              &#34;title&#34; : &#34;Tarfile infinite loop during parsing with negative member offset&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.4,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;              &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.3,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;              &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;              &#34;title&#34; : &#34;URL parser allowed square brackets in domain names&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.2,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;              &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.0,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;              &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;              &#34;title&#34; : &#34;ZIP64 End of Central Directory (EOCD) Locator record offset not checked&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.0,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;              &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 2.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-47273&#34;,&#xA;                &#34;title&#34; : &#34;setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-47273&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;                &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;                &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;                &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile infinite loop during parsing with negative member offset&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;                &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;                &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;                &#34;title&#34; : &#34;URL parser allowed square brackets in domain names&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;                &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;                &#34;title&#34; : &#34;ZIP64 End of Central Directory (EOCD) Locator record offset not checked&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28757&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28757&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45490&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45490&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8176&#34;,&#xA;                &#34;title&#34; : &#34;Libexpat: expat: improper restriction of xml entity expansion depth in libexpat&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45492&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45492&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-50602&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-50602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-59375&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-59375&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;              &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2026-21945&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21945&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-64720&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-64720&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-65018&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-65018&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-21933&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.1,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21933&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-21925&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21925&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-47273&#34;,&#xA;                &#34;title&#34; : &#34;setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-47273&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/javapackages-filesystem@5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6?arch=noarch&amp;distro=rhel-8.10&amp;upstream=javapackages-tools-5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-48734&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-48734&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2019-10086&#34;,&#xA;                &#34;title&#34; : &#34;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-10086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-48734&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-48734&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;                &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;                &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;                &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile infinite loop during parsing with negative member offset&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;                &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;                &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;                &#34;title&#34; : &#34;URL parser allowed square brackets in domain names&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;                &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;                &#34;title&#34; : &#34;ZIP64 End of Central Directory (EOCD) Locator record offset not checked&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=cups-2.2.6-67.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-58060&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58060&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-47175&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-47175&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-34241&#34;,&#xA;                &#34;title&#34; : &#34;CUPS vulnerable to use-after-free in cupsdAcceptClient()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-34241&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26691&#34;,&#xA;                &#34;title&#34; : &#34;A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26691&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32360&#34;,&#xA;                &#34;title&#34; : &#34;An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32360&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-58364&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58364&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32324&#34;,&#xA;                &#34;title&#34; : &#34;OpenPrinting CUPS vulnerable to heap buffer overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32324&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-58436&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58436&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-35235&#34;,&#xA;                &#34;title&#34; : &#34;Cupsd Listen arbitrary chmod 0140777&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-35235&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-58060&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58060&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28757&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28757&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45490&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45490&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8176&#34;,&#xA;                &#34;title&#34; : &#34;Libexpat: expat: improper restriction of xml entity expansion depth in libexpat&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45492&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45492&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-50602&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-50602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-59375&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-59375&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0553&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: incomplete fix for cve-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0553&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0567&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0567&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0361&#34;,&#xA;                &#34;title&#34; : &#34;A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0361&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32988&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls othername san export&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32988&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32990&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls certtool template parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32990&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6395&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12243&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12243&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28834&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28834&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14831&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14831&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32989&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls sct extension parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32989&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28835&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28835&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9820&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9820&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=dbus-1.12.8-27.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-42010&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42010&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42011&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42011&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42012&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42012&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-34969&#34;,&#xA;                &#34;title&#34; : &#34;D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-34969&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-42010&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42010&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/avahi-libs@0.7-27.el8_10.1?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=avahi-0.7-27.el8_10.1.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-3468&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38470&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38470&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38471&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38471&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38472&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38472&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38473&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-3502&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3502&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52615&#34;,&#xA;                &#34;title&#34; : &#34;Avahi: avahi wide-area dns uses constant source port&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52616&#34;,&#xA;                &#34;title&#34; : &#34;Avahi: avahi wide-area dns predictable transaction ids&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52616&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-3468&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27456&#34;,&#xA;                &#34;title&#34; : &#34;util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27456&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3821&#34;,&#xA;                &#34;title&#34; : &#34;An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3821&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45873&#34;,&#xA;                &#34;title&#34; : &#34;systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45873&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4598&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4598&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=alsa-lib-1.2.10-2.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2026-25068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-25068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2026-25068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-25068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;              &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;              &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;              &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15079&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15079&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13034&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13034&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14819&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14819&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1965&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14524&#34;,&#xA;                &#34;title&#34; : &#34;bearer token leak on cross-protocol redirect&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14524&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3784&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3784&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3805&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10966&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10966&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3783&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3783&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10148&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10148&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14017&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14017&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15224&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15224&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49794&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: heap use after free (uaf) leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49794&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49796&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: type confusion leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-56171&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-56171&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40304&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24928&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7425&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40303&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40303&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-25062&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-25062&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49795&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: null pointer dereference leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6021&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6021&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7424&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29824&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don&#39;t check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2&#39;s buffer functions, for example libxslt through 1.1.35, is affected as well.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29824&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39615&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9714&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9714&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-49043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-49043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28484&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28484&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29469&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the &#39;\\0&#39; value).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32414&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32414&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-26434&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-26434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6170&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: stack buffer overflow in xmllint interactive shell command handling&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.5,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6170&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3731&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3731&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3731&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3731&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libarchive-3.3.3-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4111&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4111&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4424&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-5121&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-5121&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26280&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26280&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-36227&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-36227&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-60753&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-60753&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-57970&#34;,&#xA;                &#34;title&#34; : &#34;libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-57970&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-25724&#34;,&#xA;                &#34;title&#34; : &#34;list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-25724&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27135&#34;,&#xA;                &#34;title&#34; : &#34;nghttp2 Denial of service: Assertion failure due to the missing state validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27135&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28182&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28182&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=microdnf-3.8.0-2.el8.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15079&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15079&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13034&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13034&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14819&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14819&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1965&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14524&#34;,&#xA;                &#34;title&#34; : &#34;bearer token leak on cross-protocol redirect&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14524&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3784&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3784&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3805&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10966&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10966&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3783&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3783&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10148&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10148&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14017&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14017&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15224&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15224&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49794&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: heap use after free (uaf) leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49794&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49796&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: type confusion leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-56171&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-56171&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40304&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24928&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7425&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40303&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40303&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-25062&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-25062&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49795&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: null pointer dereference leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6021&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6021&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7424&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29824&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don&#39;t check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2&#39;s buffer functions, for example libxslt through 1.1.35, is affected as well.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29824&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39615&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9714&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9714&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-49043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-49043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28484&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28484&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29469&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the &#39;\\0&#39; value).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32414&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32414&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-26434&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-26434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6170&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: stack buffer overflow in xmllint interactive shell command handling&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.5,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6170&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libksba-1.3.5-9.el8_7.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3515&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3515&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-47629&#34;,&#xA;                &#34;title&#34; : &#34;Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-47629&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3515&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3515&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnupg2-2.2.20-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2026-24882&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-24882&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68973&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68973&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-34903&#34;,&#xA;                &#34;title&#34; : &#34;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-34903&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68972&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68972&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2026-24882&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-24882&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3731&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3731&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3731&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3731&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libarchive-3.3.3-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4111&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4111&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4424&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-5121&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-5121&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26280&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26280&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-36227&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-36227&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-60753&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-60753&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-57970&#34;,&#xA;                &#34;title&#34; : &#34;libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-57970&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-25724&#34;,&#xA;                &#34;title&#34; : &#34;list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-25724&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glib2-2.56.4-168.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-13601&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in in g_escape_uri_string()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52533&#34;,&#xA;                &#34;title&#34; : &#34;gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing &#39;\\0&#39; character.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32611&#34;,&#xA;                &#34;title&#34; : &#34;G_variant_byteswap() can take a long time with some non-normal inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32611&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32665&#34;,&#xA;                &#34;title&#34; : &#34;Gvariant deserialisation does not match spec for non-normal data&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32665&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14512&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14512&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29499&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29499&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14087&#34;,&#xA;                &#34;title&#34; : &#34;Glib: glib: buffer underflow in gvariant parser leads to heap corruption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14087&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4373&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4373&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-34397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.8,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-34397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-13601&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in in g_escape_uri_string()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsolv-0.7.20-6.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-33928&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33929&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33929&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33930&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33930&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33938&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-46877&#34;,&#xA;                &#34;title&#34; : &#34;jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46877&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28863&#34;,&#xA;                &#34;title&#34; : &#34;node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28863&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44568&#34;,&#xA;                &#34;title&#34; : &#34;Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 &amp; line 1995), which could cause a remote Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44568&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-3200&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3200&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-33928&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0553&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: incomplete fix for cve-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0553&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0567&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0567&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0361&#34;,&#xA;                &#34;title&#34; : &#34;A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0361&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32988&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls othername san export&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32988&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32990&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls certtool template parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32990&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6395&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12243&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12243&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28834&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28834&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14831&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14831&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32989&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls sct extension parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32989&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28835&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28835&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9820&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9820&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27135&#34;,&#xA;                &#34;title&#34; : &#34;nghttp2 Denial of service: Assertion failure due to the missing state validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27135&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28182&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28182&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27456&#34;,&#xA;                &#34;title&#34; : &#34;util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27456&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3821&#34;,&#xA;                &#34;title&#34; : &#34;An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3821&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45873&#34;,&#xA;                &#34;title&#34; : &#34;systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45873&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4598&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4598&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=file-5.33-27.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-48554&#34;,&#xA;                &#34;title&#34; : &#34;File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: \&#34;File\&#34; is the name of an Open Source project.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-48554&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-48554&#34;,&#xA;                &#34;title&#34; : &#34;File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: \&#34;File\&#34; is the name of an Open Source project.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-48554&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=tar-1.30-11.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2025-45582&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.6,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-45582&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-48303&#34;,&#xA;              &#34;title&#34; : &#34;GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-48303&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lz4-1.8.3-5.el8_10.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=rootfiles-8.1-22.el8.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsemanage-2.9-12.el8_10.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=shadow-utils-4.6-23.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-4641&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.7,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-4641&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-56433&#34;,&#xA;              &#34;title&#34; : &#34;shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.6,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-56433&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;     &#xD;100 1010k    0  649k  100  360k  1020k   567k --:--:-- --:--:-- --:--:-- 1585k&#xA;           &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          } ]&#xA;        }&#xA;      }&#xA;    }&#xA;  },&#xA;  &#34;licenses&#34; : [ {&#xA;    &#34;status&#34; : {&#xA;      &#34;ok&#34; : false,&#xA;      &#34;name&#34; : &#34;deps.dev&#34;,&#xA;      &#34;code&#34; : 400,&#xA;      &#34;message&#34; : &#34;Bad Request: invalid purl \&#34;pkg:maven/io.github.stuartwdouglas.hacbstest.Main/hacbs-test\&#34; at request index 24&#34;,&#xA;      &#34;warnings&#34; : { }&#xA;    },&#xA;    &#34;summary&#34; : {&#xA;      &#34;total&#34; : 1,&#xA;      &#34;concluded&#34; : 120,&#xA;      &#34;permissive&#34; : 1,&#xA;      &#34;weakCopyleft&#34; : 0,&#xA;      &#34;strongCopyleft&#34; : 0,&#xA;      &#34;unknown&#34; : 0,&#xA;      &#34;deprecated&#34; : 0,&#xA;      &#34;osiApproved&#34; : 1,&#xA;      &#34;fsfLibre&#34; : 1&#xA;    },&#xA;    &#34;packages&#34; : {&#xA;      &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=p11-kit-0.23.22-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libxcrypt@4.1.1-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxcrypt-4.1.1-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sed-4.5-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/filesystem@3.8-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=filesystem-3.8-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsolv-0.7.20-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsemanage-2.9-12.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/nettle@3.4.1-7.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nettle-3.4.1-7.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libverto@0.3.2-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libverto-0.3.2-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpg-pubkey@fd431d51-4ae0493b?distro=rhel-8.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gdbm-libs@1.18-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gdbm-1.18-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libunistring@0.9.9-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libunistring-0.9.9-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/platform-python@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=shadow-utils-4.6-23.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/json-c@0.13.1-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=json-c-0.13.1-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libyaml@0.1.7-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libyaml-0.1.7-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libksba-1.3.5-9.el8_7.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=file-5.33-27.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpgme@1.13.1-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gpgme-1.13.1-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libacl@2.2.53-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=acl-2.2.53-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libarchive-3.3.3-7.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libmodulemd@2.13.0-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libmodulemd-2.13.0-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=p11-kit-0.23.22-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zstd-1.4.4-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/langpacks-en@1.0-12.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=langpacks-1.0-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/keyutils-libs@1.5.10-9.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=keyutils-1.5.10-9.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:github/beatlabs/delete-old-branches-action@v0.0.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/findutils@4.6.0-24.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=findutils-4.6.0-24.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=attr-2.4.48-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/npth@1.5-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=npth-1.5-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/librepo@1.14.2-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=librepo-1.14.2-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=dbus-1.12.8-27.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glib2-2.56.4-168.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/chkconfig@1.19.2-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=chkconfig-1.19.2-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=tar-1.30-11.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdb@5.3.28-42.el8_4?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdb-5.3.28-42.el8_4.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/platform-python-setuptools@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/librhsm@0.0.3-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=librhsm-0.0.3-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/publicsuffix-list-dafsa@20180723-1.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=publicsuffix-list-20180723-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpg-pubkey@d4082792-5b32db75?distro=rhel-8.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/readline@7.0-10.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=readline-7.0-10.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdnf@0.63.0-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdnf-0.63.0-21.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libusbx@1.0.23-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libusbx-1.0.23-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsigsegv@2.11-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsigsegv-2.11-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ca-certificates@2025.2.80_v9.0.304-80.2.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ca-certificates-2025.2.80_v9.0.304-80.2.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gawk-4.2.1-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libnsl2@1.2.0-2.20180605git4a062cf.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libnsl2-1.2.0-2.20180605git4a062cf.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/crypto-policies-scripts@20230731-1.git3177e06.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=crypto-policies-20230731-1.git3177e06.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/basesystem@11-5.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=basesystem-11-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=popt-1.18-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libidn2@2.2.0-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libidn2-2.2.0-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/setup@2.12.2-9.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=setup-2.12.2-9.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/tzdata@2026a-1.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=tzdata-2026a-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/grep@3.1-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=grep-3.1-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/mpfr@3.1.6-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=mpfr-3.1.6-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/redhat-release@8.10-0.3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=redhat-release-8.10-0.3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libassuan@2.5.1-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libassuan-2.5.1-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=elfutils-0.190-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/json-glib@1.4.4-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=json-glib-1.4.4-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gobject-introspection@1.56.1-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gobject-introspection-1.56.1-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnupg2-2.2.20-4.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libselinux@2.9-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libselinux-2.9-11.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsepol@2.9-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsepol-2.9-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:github/actions/checkout@v4&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgpg-error@1.31-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgpg-error-1.31-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=rootfiles-8.1-22.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/info@6.5-7.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=texinfo-6.5-7.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdb-utils@5.3.28-42.el8_4?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdb-5.3.28-42.el8_4.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libpsl@0.20.2-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libpsl-0.20.2-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=coreutils-8.30-17.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcap-ng@0.7.11-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-ng-0.7.11-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=cyrus-sasl-2.1.27-6.el8_5.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/crypto-policies@20230731-1.git3177e06.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=crypto-policies-20230731-1.git3177e06.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libffi@3.1-24.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libffi-3.1-24.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/pcre@8.42-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre-8.42-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gdbm@1.18-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gdbm-1.18-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/audit-libs@3.1.2-1.el8_10.1?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=audit-3.1.2-1.el8_10.1.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lz4-1.8.3-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:pypi/setuptools@39.2.0&#34; : {&#xA;        &#34;concluded&#34; : {&#xA;          &#34;identifiers&#34; : [ {&#xA;            &#34;id&#34; : &#34;MIT&#34;,&#xA;            &#34;name&#34; : &#34;MIT License&#34;,&#xA;            &#34;isDeprecated&#34; : false,&#xA;            &#34;isOsiApproved&#34; : true,&#xA;            &#34;isFsfLibre&#34; : true,&#xA;            &#34;category&#34; : &#34;PERMISSIVE&#34;&#xA;          } ],&#xA;          &#34;expression&#34; : &#34;MIT&#34;,&#xA;          &#34;name&#34; : &#34;MIT License&#34;,&#xA;          &#34;category&#34; : &#34;PERMISSIVE&#34;,&#xA;          &#34;source&#34; : &#34;deps.dev&#34;,&#xA;          &#34;sourceUrl&#34; : &#34;https://api.deps.dev&#34;&#xA;        },&#xA;        &#34;evidence&#34; : [ {&#xA;          &#34;identifiers&#34; : [ {&#xA;            &#34;id&#34; : &#34;MIT&#34;,&#xA;            &#34;name&#34; : &#34;MIT License&#34;,&#xA;            &#34;isDeprecated&#34; : false,&#xA;            &#34;isOsiApproved&#34; : true,&#xA;            &#34;isFsfLibre&#34; : true,&#xA;            &#34;category&#34; : &#34;PERMISSIVE&#34;&#xA;          } ],&#xA;          &#34;expression&#34; : &#34;MIT&#34;,&#xA;          &#34;name&#34; : &#34;MIT License&#34;,&#xA;          &#34;category&#34; : &#34;PERMISSIVE&#34;,&#xA;          &#34;source&#34; : &#34;deps.dev&#34;,&#xA;          &#34;sourceUrl&#34; : &#34;https://api.deps.dev&#34;&#xA;        } ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      }&#xA;    }&#xA;  } ]&#xA;}&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28-tpa-scan-pod | container step-oci-attach-report: &#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;Attaching tpa-report-amd64.json to quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd@sha256:3256c4ec347b39c20f504484f30eefb1130437a2d703e8e4d257cf3367938d87&#xA;[retry] executing: oras attach --no-tty --format go-template=\{\{.digest\}\} --registry-config /tmp/auth/config.json --artifact-type application/vnd.redhat.tpa-report+json quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd@sha256:3256c4ec347b39c20f504484f30eefb1130437a2d703e8e4d257cf3367938d87 tpa-report-amd64.json:application/vnd.redhat.tpa-report+json&#xA;&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fst28-tpa-scan-pod | container step-conftest-vulnerabilities: &#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/tekton/home/tpa-report-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 4,&#xA;&#x9;&#x9;&#34;warnings&#34;: [&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 6 critical vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-40896, CVE-2025-49794, CVE-2025-49796), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-40896, CVE-2025-49794, CVE-2025-49796), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-3596)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_critical_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 6&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 115 high vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: osv-github. Affected dependencies: pkg:pypi/setuptools@39.2.0 [direct] (CVE-2024-6345, CVE-2022-40897); Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [direct] (CVE-2023-2953), pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm [direct] (CVE-2026-21945, CVE-2025-64720, CVE-2025-65018), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-6345, CVE-2025-47273), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-52425, CVE-2024-28757, CVE-2024-45490, CVE-2024-45491, CVE-2024-8176), pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtirpc-1.1.4-12.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-46828), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-6345, CVE-2025-47273), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/javapackages-filesystem@5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6?arch=noarch\u0026distro=rhel-8.10\u0026upstream=javapackages-tools-5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-48734, CVE-2019-10086), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=cups-2.2.6-67.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-58060, CVE-2024-47175, CVE-2023-34241), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-52425, CVE-2024-28757, CVE-2024-45490, CVE-2024-45491, CVE-2024-8176), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-2509, CVE-2024-0553, CVE-2024-0567, CVE-2023-0361), pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtirpc-1.1.4-12.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-46828), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-44964), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2025-15079, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-56171, CVE-2022-40304, CVE-2025-24928, CVE-2025-7425, CVE-2022-40303, CVE-2024-25062, CVE-2025-32415, CVE-2025-49795, CVE-2025-6021, CVE-2025-7424, CVE-2022-29824), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5914, CVE-2026-4111, CVE-2026-4424, CVE-2026-5121), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-44487, CVE-2026-27135), pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=brotli-1.0.6-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6176), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2953), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2025-15079, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-56171, CVE-2022-40304, CVE-2025-24928, CVE-2025-7425, CVE-2022-40303, CVE-2024-25062, CVE-2025-32415, CVE-2025-49795, CVE-2025-6021, CVE-2025-7424, CVE-2022-29824), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libksba-1.3.5-9.el8_7.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-3515, CVE-2022-47629), pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnupg2-2.2.20-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2026-24882, CVE-2025-68973), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5914, CVE-2026-4111, CVE-2026-4424, CVE-2026-5121), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-13601, CVE-2024-52533), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-33928, CVE-2021-33929, CVE-2021-33930, CVE-2021-33938, CVE-2021-46877), pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=brotli-1.0.6-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6176), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-2509, CVE-2024-0553, CVE-2024-0567, CVE-2023-0361), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-44487, CVE-2026-27135), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2953), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_high_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 115&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 185 medium vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm [direct] (CVE-2026-21933, CVE-2026-21925), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [direct] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm [direct] (CVE-2025-45582, CVE-2022-48303), pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm [direct] (CVE-2023-4641), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-40897), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-45492, CVE-2024-50602, CVE-2025-59375), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-pip-9.0.3-24.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2007-4559), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-40897), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=cups-2.2.6-67.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-26691, CVE-2023-32360, CVE-2025-58364, CVE-2023-32324, CVE-2025-58436, CVE-2024-35235), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-45492, CVE-2024-50602, CVE-2025-59375), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-32988, CVE-2025-32990, CVE-2025-6395, CVE-2023-5981, CVE-2024-12243, CVE-2024-28834, CVE-2025-14831, CVE-2025-32989, CVE-2024-28835, CVE-2025-9820), pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=dbus-1.12.8-27.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-42010, CVE-2022-42011, CVE-2022-42012, CVE-2023-34969), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519, CVE-2021-44964), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/avahi-libs@0.7-27.el8_10.1?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=avahi-0.7-27.el8_10.1.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-3468, CVE-2023-1981, CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473, CVE-2021-3502, CVE-2024-52615, CVE-2024-52616), pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104, CVE-2026-27456), pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=systemd-239-82.el8_10.15.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-7008, CVE-2022-3821, CVE-2022-4415, CVE-2022-45873, CVE-2025-4598), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2236), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-pip-9.0.3-24.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2007-4559), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=alsa-lib-1.2.10-2.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2026-25068), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32206, CVE-2023-23916, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-13034, CVE-2025-14819, CVE-2026-1965, CVE-2022-32206, CVE-2023-23916, CVE-2025-14524, CVE-2026-3784, CVE-2026-3805, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2025-10966, CVE-2026-3783, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2025-10148, CVE-2025-14017, CVE-2025-15224, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-39615, CVE-2025-9714, CVE-2022-49043, CVE-2023-28484, CVE-2023-29469, CVE-2025-32414, CVE-2025-26434), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-48795, CVE-2026-3731, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-48795, CVE-2026-3731, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-26280, CVE-2022-36227, CVE-2025-60753, CVE-2024-57970, CVE-2025-25724), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-28182), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519, CVE-2021-44964), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32206, CVE-2023-23916, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-13034, CVE-2025-14819, CVE-2026-1965, CVE-2022-32206, CVE-2023-23916, CVE-2025-14524, CVE-2026-3784, CVE-2026-3805, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2025-10966, CVE-2026-3783, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2025-10148, CVE-2025-14017, CVE-2025-15224, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-39615, CVE-2025-9714, CVE-2022-49043, CVE-2023-28484, CVE-2023-29469, CVE-2025-32414, CVE-2025-26434), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnupg2-2.2.20-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-34903, CVE-2025-68972), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-48795, CVE-2026-3731, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-48795, CVE-2026-3731, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-26280, CVE-2022-36227, CVE-2025-60753, CVE-2024-57970, CVE-2025-25724), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-32611, CVE-2023-32665, CVE-2025-14512, CVE-2023-29499, CVE-2025-14087, CVE-2025-4373), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-28863, CVE-2021-44568), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-32988, CVE-2025-32990, CVE-2025-6395, CVE-2023-5981, CVE-2024-12243, CVE-2024-28834, CVE-2025-14831, CVE-2025-32989, CVE-2024-28835, CVE-2025-9820), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-28182), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519, CVE-2021-44964), pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104, CVE-2026-27456), pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2236), pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=systemd-239-82.el8_10.15.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-7008, CVE-2022-3821, CVE-2022-4415, CVE-2022-45873, CVE-2025-4598), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=file-5.33-27.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-48554), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2019-12900)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_medium_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 185&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 14 low vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm [direct] (CVE-2024-56433), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6170), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6170), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-34397), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-3200), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-2602)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_low_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 14&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;]&#xA;&#x9;}&#xA;]&#xA;{&#34;vulnerabilities&#34;:{&#34;critical&#34;:6,&#34;high&#34;:115,&#34;medium&#34;:185,&#34;low&#34;:14,&#34;unknown&#34;:0},&#34;unpatched_vulnerabilities&#34;:{&#34;critical&#34;:0,&#34;high&#34;:0,&#34;medium&#34;:0,&#34;low&#34;:0,&#34;unknown&#34;:0}}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd:on-pr-bc682fe28febe268b1ae39157fc01568df7437f8&#34;, &#34;digests&#34;: [&#34;sha256:3256c4ec347b39c20f504484f30eefb1130437a2d703e8e4d257cf3367938d87&#34;]}}&#xA;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T14:02:13+00:00&#34;,&#34;note&#34;:&#34;Task tpa-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by TPA.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;New PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh found after retrigger for component forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh found for Component forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh reason: Failed&#xA;attempt 2/3: PipelineRun &#34;test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh&#34; failed: &#xA; pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh-init-pod | init container: prepare&#xA;2026/04/22 14:05:10 Entrypoint initialization&#xA;&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh-init-pod | container step-init: &#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-22T14:05:12Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;&#xA; pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh-tpa-scan-pod | init container: prepare&#xA;2026/04/22 14:10:21 Entrypoint initialization&#xA;&#xA; pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh-tpa-scan-pod | init container: place-scripts&#xA;2026/04/22 14:10:22 Decoded script /tekton/scripts/script-0-r5slz&#xA;2026/04/22 14:10:22 Decoded script /tekton/scripts/script-1-jfv2v&#xA;2026/04/22 14:10:22 Decoded script /tekton/scripts/script-2-hfsp8&#xA;&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh-tpa-scan-pod | container step-get-vulnerabilities: &#xA;Inspecting raw image manifest quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd@sha256:35f81c0f5e5b92451fcf6ad8d2fbbf001b6cd2964035acc1b8a84f26c5c910df.&#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations.&#xA;WARNING: Downloading SBOMs this way does not ensure its authenticity. If you want to ensure a tamper-proof SBOM, download it using &#39;cosign download attestation &lt;image uri&gt;&#39;.&#xA;Found SBOM of media type: text/spdx+json&#xA;Running TPA scan on amd64 image manifest...&#xA;  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current&#xA;                                 Dload  Upload   Total   Spent    Left  Speed&#xA;&#xD;  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0&#xD;100  360k    0     0  100  360k      0   481k --:--:-- --:--:-- --:--:--  480k{&#xA;  &#34;scanned&#34; : {&#xA;    &#34;total&#34; : 152,&#xA;    &#34;direct&#34; : 25,&#xA;    &#34;transitive&#34; : 127&#xA;  },&#xA;  &#34;providers&#34; : {&#xA;    &#34;rhtpa&#34; : {&#xA;      &#34;status&#34; : {&#xA;        &#34;ok&#34; : true,&#xA;        &#34;name&#34; : &#34;rhtpa&#34;,&#xA;        &#34;code&#34; : 200,&#xA;        &#34;message&#34; : &#34;OK&#34;,&#xA;        &#34;warnings&#34; : {&#xA;          &#34;pkg:maven/io.github.stuartwdouglas.hacbstest.Main/hacbs-test&#34; : [ &#34;Unable to process: missing version component&#34; ]&#xA;        }&#xA;      },&#xA;      &#34;sources&#34; : {&#xA;        &#34;osv-github&#34; : {&#xA;          &#34;summary&#34; : {&#xA;            &#34;direct&#34; : 2,&#xA;            &#34;transitive&#34; : 0,&#xA;            &#34;total&#34; : 2,&#xA;            &#34;dependencies&#34; : 1,&#xA;            &#34;critical&#34; : 0,&#xA;            &#34;high&#34; : 2,&#xA;            &#34;medium&#34; : 0,&#xA;            &#34;low&#34; : 0,&#xA;            &#34;remediations&#34; : 0,&#xA;            &#34;recommendations&#34; : 0,&#xA;            &#34;unscanned&#34; : 0&#xA;          },&#xA;          &#34;dependencies&#34; : [ {&#xA;            &#34;ref&#34; : &#34;pkg:pypi/setuptools@39.2.0&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;              &#34;source&#34; : &#34;osv-github&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          } ]&#xA;        },&#xA;        &#34;redhat-csaf&#34; : {&#xA;          &#34;summary&#34; : {&#xA;            &#34;direct&#34; : 50,&#xA;            &#34;transitive&#34; : 345,&#xA;            &#34;total&#34; : 395,&#xA;            &#34;dependencies&#34; : 57,&#xA;            &#34;critical&#34; : 7,&#xA;            &#34;high&#34; : 133,&#xA;            &#34;medium&#34; : 236,&#xA;            &#34;low&#34; : 19,&#xA;            &#34;remediations&#34; : 0,&#xA;            &#34;recommendations&#34; : 0,&#xA;            &#34;unscanned&#34; : 0&#xA;          },&#xA;          &#34;dependencies&#34; : [ {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;              &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;              &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.6,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;              &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;              &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;              &#34;title&#34; : &#34;Tarfile infinite loop during parsing with negative member offset&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.4,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;              &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.3,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;              &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;              &#34;title&#34; : &#34;URL parser allowed square brackets in domain names&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.2,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;              &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.0,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;              &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;              &#34;title&#34; : &#34;ZIP64 End of Central Directory (EOCD) Locator record offset not checked&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.0,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;              &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 2.7,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-47273&#34;,&#xA;                &#34;title&#34; : &#34;setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-47273&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;                &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;                &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;                &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile infinite loop during parsing with negative member offset&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;                &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;                &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;                &#34;title&#34; : &#34;URL parser allowed square brackets in domain names&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;                &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;                &#34;title&#34; : &#34;ZIP64 End of Central Directory (EOCD) Locator record offset not checked&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28757&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28757&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45490&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45490&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8176&#34;,&#xA;                &#34;title&#34; : &#34;Libexpat: expat: improper restriction of xml entity expansion depth in libexpat&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45492&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45492&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-50602&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-50602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-59375&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-59375&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;              &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2026-21945&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.5,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21945&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-64720&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-64720&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2025-65018&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 7.1,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-65018&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-21933&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.1,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21933&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2026-21925&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.8,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2026-21925&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-47273&#34;,&#xA;                &#34;title&#34; : &#34;setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-47273&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40897&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40897&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-6345&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6345&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/javapackages-filesystem@5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6?arch=noarch&amp;distro=rhel-8.10&amp;upstream=javapackages-tools-5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-48734&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-48734&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2019-10086&#34;,&#xA;                &#34;title&#34; : &#34;In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-10086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-48734&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-48734&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42919&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42919&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6597&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6597&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2015-20107&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2015-20107&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12718&#34;,&#xA;                &#34;title&#34; : &#34;Bypass extraction filter to modify file metadata outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12718&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4517&#34;,&#xA;                &#34;title&#34; : &#34;Arbitrary writes via tarfile realpath overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4517&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-10735&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-10735&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45061&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45061&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-24329&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-24329&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6232&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6232&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-12084&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-12084&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4138&#34;,&#xA;                &#34;title&#34; : &#34;Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4138&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4435&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile extracts filtered members when errorlevel=0&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4435&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8194&#34;,&#xA;                &#34;title&#34; : &#34;Tarfile infinite loop during parsing with negative member offset&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8194&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-28861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-28861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4330&#34;,&#xA;                &#34;title&#34; : &#34;Extraction filter bypass for linking outside extraction directory&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4330&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15366&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15366&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15367&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15367&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1299&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1299&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4519&#34;,&#xA;                &#34;title&#34; : &#34;webbrowser.open() allows leading dashes in URLs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6923&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6923&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0938&#34;,&#xA;                &#34;title&#34; : &#34;URL parser allowed square brackets in domain names&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13836&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13836&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-9287&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-9287&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8088&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8088&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-7592&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-7592&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0865&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0865&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6069&#34;,&#xA;                &#34;title&#34; : &#34;HTMLParser quadratic complexity when processing malformed inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6069&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8291&#34;,&#xA;                &#34;title&#34; : &#34;ZIP64 End of Central Directory (EOCD) Locator record offset not checked&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8291&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6075&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6075&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-11168&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-11168&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4032&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5642&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overread when using an empty list with SSLContext.set_npn_protocols()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5642&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-40217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-40217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=cups-2.2.6-67.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-58060&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58060&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-47175&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-47175&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-34241&#34;,&#xA;                &#34;title&#34; : &#34;CUPS vulnerable to use-after-free in cupsdAcceptClient()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-34241&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26691&#34;,&#xA;                &#34;title&#34; : &#34;A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26691&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32360&#34;,&#xA;                &#34;title&#34; : &#34;An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32360&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-58364&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58364&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32324&#34;,&#xA;                &#34;title&#34; : &#34;OpenPrinting CUPS vulnerable to heap buffer overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32324&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-58436&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58436&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-35235&#34;,&#xA;                &#34;title&#34; : &#34;Cupsd Listen arbitrary chmod 0140777&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-35235&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-58060&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-58060&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28757&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28757&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45490&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45490&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-8176&#34;,&#xA;                &#34;title&#34; : &#34;Libexpat: expat: improper restriction of xml entity expansion depth in libexpat&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-8176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-45492&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-45492&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-50602&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-50602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-59375&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-59375&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-52425&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-52425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0553&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: incomplete fix for cve-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0553&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0567&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0567&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0361&#34;,&#xA;                &#34;title&#34; : &#34;A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0361&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32988&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls othername san export&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32988&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32990&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls certtool template parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32990&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6395&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12243&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12243&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28834&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28834&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14831&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14831&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32989&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls sct extension parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32989&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28835&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28835&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9820&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9820&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46828&#34;,&#xA;                &#34;title&#34; : &#34;In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46828&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=dbus-1.12.8-27.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-42010&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42010&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42011&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42011&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42012&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42012&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-34969&#34;,&#xA;                &#34;title&#34; : &#34;D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-34969&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-42010&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42010&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/avahi-libs@0.7-27.el8_10.1?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=avahi-0.7-27.el8_10.1.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-3468&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38470&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38470&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38471&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38471&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38472&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38472&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38473&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-3502&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3502&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52615&#34;,&#xA;                &#34;title&#34; : &#34;Avahi: avahi wide-area dns uses constant source port&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52616&#34;,&#xA;                &#34;title&#34; : &#34;Avahi: avahi wide-area dns predictable transaction ids&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52616&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-3468&#34;,&#xA;                &#34;title&#34; : &#34;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27456&#34;,&#xA;                &#34;title&#34; : &#34;util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27456&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3821&#34;,&#xA;                &#34;title&#34; : &#34;An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3821&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45873&#34;,&#xA;                &#34;title&#34; : &#34;systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45873&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4598&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4598&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2007-4559&#34;,&#xA;                &#34;title&#34; : &#34;Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2007-4559&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=alsa-lib-1.2.10-2.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2026-25068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-25068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2026-25068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-25068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;              &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;              &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;              &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 6.3,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15079&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15079&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13034&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13034&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14819&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14819&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1965&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14524&#34;,&#xA;                &#34;title&#34; : &#34;bearer token leak on cross-protocol redirect&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14524&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3784&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3784&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3805&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10966&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10966&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3783&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3783&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10148&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10148&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14017&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14017&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15224&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15224&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49794&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: heap use after free (uaf) leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49794&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49796&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: type confusion leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-56171&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-56171&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40304&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24928&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7425&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40303&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40303&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-25062&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-25062&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49795&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: null pointer dereference leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6021&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6021&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7424&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29824&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don&#39;t check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2&#39;s buffer functions, for example libxslt through 1.1.35, is affected as well.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29824&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39615&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9714&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9714&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-49043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-49043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28484&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28484&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29469&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the &#39;\\0&#39; value).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32414&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32414&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-26434&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-26434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6170&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: stack buffer overflow in xmllint interactive shell command handling&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.5,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6170&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3731&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3731&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3731&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3731&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libarchive-3.3.3-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4111&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4111&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4424&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-5121&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-5121&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26280&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26280&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-36227&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-36227&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-60753&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-60753&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-57970&#34;,&#xA;                &#34;title&#34; : &#34;libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-57970&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-25724&#34;,&#xA;                &#34;title&#34; : &#34;list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-25724&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27135&#34;,&#xA;                &#34;title&#34; : &#34;nghttp2 Denial of service: Assertion failure due to the missing state validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27135&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28182&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28182&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=microdnf-3.8.0-2.el8.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1473&#34;,&#xA;                &#34;title&#34; : &#34;Resource leakage when decoding certificates and keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1473&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3358&#34;,&#xA;                &#34;title&#34; : &#34;Using a Custom Cipher with NID_undef may lead to NULL encryption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3358&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3602&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address 4-byte Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3786&#34;,&#xA;                &#34;title&#34; : &#34;X.509 Email Address Variable Length Buffer Overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3786&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4450&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4450&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0215&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0215&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0216&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0216&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0217&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0217&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0401&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0401&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5363&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5363&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0286&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0286&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12797&#34;,&#xA;                &#34;title&#34; : &#34;RFC7250 handshakes with unauthenticated servers don&#39;t abort as expected&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12797&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69419&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69419&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1292&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1292&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2068&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2068&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2650&#34;,&#xA;                &#34;title&#34; : &#34;Possible DoS translating ASN.1 object identifiers&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2650&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6129&#34;,&#xA;                &#34;title&#34; : &#34;POLY1305 MAC implementation corrupts vector registers on PowerPC&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6129&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69421&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69421&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-11187&#34;,&#xA;                &#34;title&#34; : &#34;Improper validation of PBMAC1 parameters in PKCS#12 MAC verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-11187&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-1971&#34;,&#xA;                &#34;title&#34; : &#34;EDIPARTYNAME NULL pointer dereference&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-1971&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4304&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0464&#34;,&#xA;                &#34;title&#34; : &#34;Excessive Resource Usage Verifying X.509 Policy Constraints&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0464&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6237&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking invalid RSA public keys&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6237&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-5535&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-5535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-6119&#34;,&#xA;                &#34;title&#34; : &#34;Possible denial of service in X.509 name checks&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-6119&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15468&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15468&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-66199&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-66199&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69420&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69420&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22796&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4741&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4741&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9230&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9230&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0727&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0727&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15469&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-22795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-22795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1343&#34;,&#xA;                &#34;title&#34; : &#34;OCSP_basic_verify may incorrectly verify the response signing certificate&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1343&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-2097&#34;,&#xA;                &#34;title&#34; : &#34;AES OCB fails to encrypt some bytes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2097&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0465&#34;,&#xA;                &#34;title&#34; : &#34;Invalid certificate policies in leaf certificates are silently ignored&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0465&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0466&#34;,&#xA;                &#34;title&#34; : &#34;Certificate policy check not enabled&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0466&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2975&#34;,&#xA;                &#34;title&#34; : &#34;AES-SIV implementation ignores empty associated data entries&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3446&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3446&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-3817&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DH q parameter value&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-3817&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5678&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5678&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-4603&#34;,&#xA;                &#34;title&#34; : &#34;Excessive time spent checking DSA keys and parameters&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-4603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1255&#34;,&#xA;                &#34;title&#34; : &#34;Input buffer over-read in AES-XTS implementation on 64 bit ARM&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1255&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4203&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4203&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68160&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68160&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69418&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69418&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2511&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2511&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;                &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-22576&#34;,&#xA;                &#34;title&#34; : &#34;An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-22576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38545&#34;,&#xA;                &#34;title&#34; : &#34;This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \&#34;let the host resolve the name\&#34; could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38545&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15079&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15079&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27775&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27775&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27782&#34;,&#xA;                &#34;title&#34; : &#34;libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27782&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-2398&#34;,&#xA;                &#34;title&#34; : &#34;HTTP/2 push headers memory-leak&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2398&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13034&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13034&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14819&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14819&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-1965&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-1965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32206&#34;,&#xA;                &#34;title&#34; : &#34;curl &lt; 7.84.0 supports \&#34;chained\&#34; HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32206&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-23916&#34;,&#xA;                &#34;title&#34; : &#34;An allocation of resources without limits or throttling vulnerability exists in curl &lt;v7.88.0 based on the \&#34;chained\&#34; HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable \&#34;links\&#34; in this \&#34;decompression chain\&#34; wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a \&#34;malloc bomb\&#34;, making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-23916&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14524&#34;,&#xA;                &#34;title&#34; : &#34;bearer token leak on cross-protocol redirect&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14524&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3784&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3784&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3805&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-43552&#34;,&#xA;                &#34;title&#34; : &#34;A use after free vulnerability exists in curl &lt;7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-43552&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27535&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl &lt;8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27535&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27536&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists libcurl &lt;8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27536&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28321&#34;,&#xA;                &#34;title&#34; : &#34;An improper certificate validation vulnerability exists in curl &lt;v8.1.0 in the way it supports matching of wildcard patterns when listed as \&#34;Subject Alternative Name\&#34; in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28321&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10966&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10966&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3783&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3783&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27538&#34;,&#xA;                &#34;title&#34; : &#34;An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27538&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32208&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32208&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-46218&#34;,&#xA;                &#34;title&#34; : &#34;This flaw allows a malicious HTTP server to set \&#34;super cookies\&#34; in curl that\nare then passed back to more origins than what is otherwise allowed or\npossible. This allows a site to set cookies that then would get sent to\ndifferent and unrelated sites and domains.\n\nIt could do this by exploiting a mixed case flaw in curl&#39;s function that\nverifies a given cookie domain against the Public Suffix List (PSL). For\nexample a cookie could be set with `domain=co.UK` when the URL used a lower\ncase hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-46218&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9086&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9086&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27774&#34;,&#xA;                &#34;title&#34; : &#34;An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27774&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-32221&#34;,&#xA;                &#34;title&#34; : &#34;When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32221&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-10148&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-10148&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14017&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14017&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15224&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15224&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-27776&#34;,&#xA;                &#34;title&#34; : &#34;A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-27776&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27533&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability in input validation exists in curl &lt;8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and \&#34;telnet options\&#34; during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application&#39;s intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-27534&#34;,&#xA;                &#34;title&#34; : &#34;A path traversal vulnerability exists in curl &lt;8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user&#39;s home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-27534&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28322&#34;,&#xA;                &#34;title&#34; : &#34;An information disclosure vulnerability exists in curl &lt;v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28322&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-38546&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-38546&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35252&#34;,&#xA;                &#34;title&#34; : &#34;When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\&#34;sister site\&#34; to deny service to all siblings.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.1,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35252&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-32207&#34;,&#xA;                &#34;title&#34; : &#34;When curl &lt; 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.8,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-32207&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49794&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: heap use after free (uaf) leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49794&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49796&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: type confusion leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49796&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-56171&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-56171&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40304&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24928&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7425&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7425&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-40303&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-40303&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-25062&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-25062&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-49795&#34;,&#xA;                &#34;title&#34; : &#34;Libxml: null pointer dereference leads to denial of service (dos)&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-49795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6021&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6021&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-7424&#34;,&#xA;                &#34;title&#34; : &#34;Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-7424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29824&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don&#39;t check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2&#39;s buffer functions, for example libxslt through 1.1.35, is affected as well.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29824&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39615&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39615&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9714&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9714&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-49043&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-49043&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-28484&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-28484&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29469&#34;,&#xA;                &#34;title&#34; : &#34;An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the &#39;\\0&#39; value).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29469&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32414&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32414&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-26434&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-26434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6170&#34;,&#xA;                &#34;title&#34; : &#34;Libxml2: stack buffer overflow in xmllint interactive shell command handling&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 2.5,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6170&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-40896&#34;,&#xA;                &#34;title&#34; : &#34;In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \&#34;checked\&#34;). This makes classic XXE attacks possible.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.1,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-40896&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-42898&#34;,&#xA;                &#34;title&#34; : &#34;PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has \&#34;a similar bug.\&#34;&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-42898&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-39975&#34;,&#xA;                &#34;title&#34; : &#34;kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-39975&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26462&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26462&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37370&#34;,&#xA;                &#34;title&#34; : &#34;In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37370&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2020-17049&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos KDC Security Feature Bypass Vulnerability&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-17049&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-36054&#34;,&#xA;                &#34;title&#34; : &#34;lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-36054&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-37371&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-37371&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-24528&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-24528&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26458&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-26461&#34;,&#xA;                &#34;title&#34; : &#34;Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-26461&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3576&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3576&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-3596&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 9.0,&#xA;                &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-3596&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-31115&#34;,&#xA;                &#34;title&#34; : &#34;XZ has a heap-use-after-free bug in threaded .xz decoder&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-31115&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1271&#34;,&#xA;                &#34;title&#34; : &#34;An arbitrary file write vulnerability was found in GNU gzip&#39;s zgrep utility. When zgrep is applied on the attacker&#39;s chosen file name (for example, a crafted file name), this can overwrite an attacker&#39;s content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1271&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libksba-1.3.5-9.el8_7.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3515&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3515&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-47629&#34;,&#xA;                &#34;title&#34; : &#34;Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-47629&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3515&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3515&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnupg2-2.2.20-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2026-24882&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-24882&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68973&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68973&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-34903&#34;,&#xA;                &#34;title&#34; : &#34;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-34903&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-68972&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-68972&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2026-24882&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-24882&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3731&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3731&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5987&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: invalid return code for chacha20 poly1305 with openssl backend&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5987&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-48795&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-48795&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3731&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3731&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2283&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2283&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6004&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6004&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-1667&#34;,&#xA;                &#34;title&#34; : &#34;A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-1667&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-6918&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.7,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-6918&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5318&#34;,&#xA;                &#34;title&#34; : &#34;Libssh: out-of-bounds read in sftp_handle()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5318&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libarchive-3.3.3-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4111&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4111&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-4424&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-4424&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-5121&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-5121&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-26280&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-26280&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-36227&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-36227&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-60753&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-60753&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-57970&#34;,&#xA;                &#34;title&#34; : &#34;libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-57970&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-25724&#34;,&#xA;                &#34;title&#34; : &#34;list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-25724&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-5914&#34;,&#xA;                &#34;title&#34; : &#34;Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5914&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glib2-2.56.4-168.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-13601&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in in g_escape_uri_string()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-52533&#34;,&#xA;                &#34;title&#34; : &#34;gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing &#39;\\0&#39; character.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-52533&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32611&#34;,&#xA;                &#34;title&#34; : &#34;G_variant_byteswap() can take a long time with some non-normal inputs&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32611&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-32665&#34;,&#xA;                &#34;title&#34; : &#34;Gvariant deserialisation does not match spec for non-normal data&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-32665&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14512&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14512&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-29499&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29499&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14087&#34;,&#xA;                &#34;title&#34; : &#34;Glib: glib: buffer underflow in gvariant parser leads to heap corruption&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14087&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4373&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4373&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-34397&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.8,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-34397&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-13601&#34;,&#xA;                &#34;title&#34; : &#34;Glib: integer overflow in in g_escape_uri_string()&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-7104&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-3277&#34;,&#xA;                &#34;title&#34; : &#34;An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.3,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-3277&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-35737&#34;,&#xA;                &#34;title&#34; : &#34;SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-35737&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6965&#34;,&#xA;                &#34;title&#34; : &#34;Integer Truncation on SQLite&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.7,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6965&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsolv-0.7.20-6.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-33928&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33929&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33929&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33930&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33930&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-33938&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-46877&#34;,&#xA;                &#34;title&#34; : &#34;jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46877&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28863&#34;,&#xA;                &#34;title&#34; : &#34;node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28863&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44568&#34;,&#xA;                &#34;title&#34; : &#34;Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 &amp; line 1995), which could cause a remote Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44568&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-3200&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-3200&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-33928&#34;,&#xA;                &#34;title&#34; : &#34;Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-33928&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-6176&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6176&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0553&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: incomplete fix for cve-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0553&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-0567&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-0567&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-0361&#34;,&#xA;                &#34;title&#34; : &#34;A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.4,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-0361&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32988&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls othername san export&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32988&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32990&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls certtool template parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32990&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-6395&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-6395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-5981&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-5981&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12243&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12243&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28834&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28834&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-14831&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14831&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-32989&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: vulnerability in gnutls sct extension parsing&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-32989&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28835&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28835&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-9820&#34;,&#xA;                &#34;title&#34; : &#34;Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-9820&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-2509&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-2509&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27135&#34;,&#xA;                &#34;title&#34; : &#34;nghttp2 Denial of service: Assertion failure due to the missing state validation&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27135&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-28182&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-28182&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-44487&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-44487&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2953&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2953&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-28805&#34;,&#xA;                &#34;title&#34; : &#34;singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-28805&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-43519&#34;,&#xA;                &#34;title&#34; : &#34;Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43519&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-44964&#34;,&#xA;                &#34;title&#34; : &#34;Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-44964&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-33099&#34;,&#xA;                &#34;title&#34; : &#34;An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-33099&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35939&#34;,&#xA;                &#34;title&#34; : &#34;It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35939&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2021-35937&#34;,&#xA;                &#34;title&#34; : &#34;A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35937&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-35938&#34;,&#xA;                &#34;title&#34; : &#34;A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-35938&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-43618&#34;,&#xA;                &#34;title&#34; : &#34;GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-43618&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-27456&#34;,&#xA;                &#34;title&#34; : &#34;util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-27456&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2025-14104&#34;,&#xA;                &#34;title&#34; : &#34;Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-14104&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-13151&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-13151&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-12133&#34;,&#xA;                &#34;title&#34; : &#34;Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-12133&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2021-46848&#34;,&#xA;                &#34;title&#34; : &#34;GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2021-46848&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2236&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2236&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-3821&#34;,&#xA;                &#34;title&#34; : &#34;An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3821&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-4415&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-4415&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-45873&#34;,&#xA;                &#34;title&#34; : &#34;systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-45873&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4598&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.7,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4598&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-7008&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-7008&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1304&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.8,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1304&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=file-5.33-27.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-48554&#34;,&#xA;                &#34;title&#34; : &#34;File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: \&#34;File\&#34; is the name of an Open Source project.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-48554&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-48554&#34;,&#xA;                &#34;title&#34; : &#34;File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: \&#34;File\&#34; is the name of an Open Source project.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-48554&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2025-15467&#34;,&#xA;              &#34;title&#34; : &#34;Stack buffer overflow in CMS (Auth)EnvelopedData parsing&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 9.8,&#xA;              &#34;severity&#34; : &#34;CRITICAL&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-15467&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=tar-1.30-11.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2025-45582&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.6,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2025-45582&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2022-48303&#34;,&#xA;              &#34;title&#34; : &#34;GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 5.5,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2022-48303&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-37434&#34;,&#xA;                &#34;title&#34; : &#34;zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-37434&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2018-25032&#34;,&#xA;                &#34;title&#34; : &#34;zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.2,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2018-25032&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lz4-1.8.3-5.el8_10.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=rootfiles-8.1-22.el8.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsemanage-2.9-12.el8_10.src.rpm&#34;,&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          }, {&#xA;            &#34;ref&#34; : &#34;pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=shadow-utils-4.6-23.el8_10.src.rpm&#34;,&#xA;            &#34;issues&#34; : [ {&#xA;              &#34;id&#34; : &#34;CVE-2023-4641&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 4.7,&#xA;              &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2023-4641&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }, {&#xA;              &#34;id&#34; : &#34;CVE-2024-56433&#34;,&#xA;              &#34;title&#34; : &#34;shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 3.6,&#xA;              &#34;severity&#34; : &#34;LOW&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-56433&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            } ],&#xA;            &#34;transitive&#34; : [ {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;u&#xD;100 1010k    0  649k  100  360k   854k   474k --:--:-- --:--:-- --:--:-- 1327k&#xA;nique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-15281&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-15281&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-3904&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-3904&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0861&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.1,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0861&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4911&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4911&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33599&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Stack-based buffer overflow in netgroup cache&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.6,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33599&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-4802&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.0,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-4802&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4527&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4527&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4806&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4806&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-4813&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.9,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-4813&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-5702&#34;,&#xA;                &#34;title&#34; : &#34;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-5702&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-0395&#34;,&#xA;                &#34;title&#34; : &#34;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.5,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-0395&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33600&#34;,&#xA;                &#34;title&#34; : &#34;nscd: Null pointer crashes after notfound response&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33600&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2026-0915&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 5.3,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2026-0915&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-8058&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.2,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-8058&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33601&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache may terminate daemon on memory allocation failure&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33601&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2024-33602&#34;,&#xA;                &#34;title&#34; : &#34;nscd: netgroup cache assumes NSS callback uses in-buffer strings&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.0,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-33602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 8.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2023-2602&#34;,&#xA;                &#34;title&#34; : &#34;A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 3.3,&#xA;                &#34;severity&#34; : &#34;LOW&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2602&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-2603&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-2603&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2025-69720&#34;,&#xA;                &#34;title&#34; : &#34;The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2025-69720&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-29458&#34;,&#xA;                &#34;title&#34; : &#34;ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-29458&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2023-29491&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.8,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2023-29491&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }, {&#xA;                &#34;id&#34; : &#34;CVE-2022-1587&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1587&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-1586&#34;,&#xA;                &#34;title&#34; : &#34;An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 7.5,&#xA;                &#34;severity&#34; : &#34;HIGH&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-1586&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2022-3715&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.6,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2022-3715&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2020-11023&#34;,&#xA;                &#34;title&#34; : &#34;Potential XSS vulnerability in jQuery&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 6.1,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2020-11023&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            }, {&#xA;              &#34;ref&#34; : &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34;,&#xA;              &#34;issues&#34; : [ {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              } ],&#xA;              &#34;highestVulnerability&#34; : {&#xA;                &#34;id&#34; : &#34;CVE-2019-12900&#34;,&#xA;                &#34;title&#34; : &#34;BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.&#34;,&#xA;                &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;                &#34;cvssScore&#34; : 4.4,&#xA;                &#34;severity&#34; : &#34;MEDIUM&#34;,&#xA;                &#34;cves&#34; : [ &#34;CVE-2019-12900&#34; ],&#xA;                &#34;unique&#34; : false&#xA;              }&#xA;            } ],&#xA;            &#34;highestVulnerability&#34; : {&#xA;              &#34;id&#34; : &#34;CVE-2024-2961&#34;,&#xA;              &#34;source&#34; : &#34;redhat-csaf&#34;,&#xA;              &#34;cvssScore&#34; : 8.8,&#xA;              &#34;severity&#34; : &#34;HIGH&#34;,&#xA;              &#34;cves&#34; : [ &#34;CVE-2024-2961&#34; ],&#xA;              &#34;unique&#34; : false&#xA;            }&#xA;          } ]&#xA;        }&#xA;      }&#xA;    }&#xA;  },&#xA;  &#34;licenses&#34; : [ {&#xA;    &#34;status&#34; : {&#xA;      &#34;ok&#34; : false,&#xA;      &#34;name&#34; : &#34;deps.dev&#34;,&#xA;      &#34;code&#34; : 400,&#xA;      &#34;message&#34; : &#34;Bad Request: invalid purl \&#34;pkg:maven/io.github.stuartwdouglas.hacbstest.Main/hacbs-test\&#34; at request index 23&#34;,&#xA;      &#34;warnings&#34; : { }&#xA;    },&#xA;    &#34;summary&#34; : {&#xA;      &#34;total&#34; : 1,&#xA;      &#34;concluded&#34; : 120,&#xA;      &#34;permissive&#34; : 1,&#xA;      &#34;weakCopyleft&#34; : 0,&#xA;      &#34;strongCopyleft&#34; : 0,&#xA;      &#34;unknown&#34; : 0,&#xA;      &#34;deprecated&#34; : 0,&#xA;      &#34;osiApproved&#34; : 1,&#xA;      &#34;fsfLibre&#34; : 1&#xA;    },&#xA;    &#34;packages&#34; : {&#xA;      &#34;pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zlib-1.2.11-25.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/p11-kit@0.23.22-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=p11-kit-0.23.22-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libxcrypt@4.1.1-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxcrypt-4.1.1-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/sed@4.5-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sed-4.5-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/filesystem@3.8-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=filesystem-3.8-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsolv-0.7.20-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsemanage-2.9-12.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/nettle@3.4.1-7.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=nettle-3.4.1-7.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libverto@0.3.2-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libverto-0.3.2-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpg-pubkey@fd431d51-4ae0493b?distro=rhel-8.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gdbm-libs@1.18-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gdbm-1.18-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=xz-5.2.4-4.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libunistring@0.9.9-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libunistring-0.9.9-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=openssl-1.1.1k-15.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lua-5.3.4-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/platform-python@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=shadow-utils-4.6-23.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/json-c@0.13.1-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=json-c-0.13.1-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtasn1-4.13-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libyaml@0.1.7-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libyaml-0.1.7-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libksba-1.3.5-9.el8_7.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=krb5-1.18.2-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=file-5.33-27.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpgme@1.13.1-12.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gpgme-1.13.1-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libacl@2.2.53-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=acl-2.2.53-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libarchive-3.3.3-7.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libmodulemd@2.13.0-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libmodulemd-2.13.0-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/p11-kit-trust@0.23.22-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=p11-kit-0.23.22-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=zstd-1.4.4-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-2.48-6.el8_9.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libtirpc-1.1.4-12.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-pip-9.0.3-24.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre2-10.32-3.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/langpacks-en@1.0-12.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=langpacks-1.0-12.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bzip2-1.0.6-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/keyutils-libs@1.5.10-9.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=keyutils-1.5.10-9.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnutls-3.6.16-8.el8_10.5.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:github/beatlabs/delete-old-branches-action@v0.0.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/findutils@4.6.0-24.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=findutils-4.6.0-24.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libattr@2.4.48-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=attr-2.4.48-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/npth@1.5-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=npth-1.5-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/librepo@1.14.2-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=librepo-1.14.2-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=dbus-1.12.8-27.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glib2-2.56.4-168.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/chkconfig@1.19.2-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=chkconfig-1.19.2-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=2&amp;upstream=tar-1.30-11.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdb@5.3.28-42.el8_4?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdb-5.3.28-42.el8_4.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=libssh-0.9.6-16.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/platform-python-setuptools@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/librhsm@0.0.3-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=librhsm-0.0.3-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/publicsuffix-list-dafsa@20180723-1.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=publicsuffix-list-20180723-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=python-setuptools-39.2.0-9.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gpg-pubkey@d4082792-5b32db75?distro=rhel-8.10&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/readline@7.0-10.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=readline-7.0-10.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdnf@0.63.0-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdnf-0.63.0-21.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libusbx@1.0.23-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libusbx-1.0.23-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsigsegv@2.11-5.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsigsegv-2.11-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=python3-3.6.8-75.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ca-certificates@2025.2.80_v9.0.304-80.2.el8_10?arch=noarch&amp;distro=rhel-8.10&amp;upstream=ca-certificates-2025.2.80_v9.0.304-80.2.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gawk@4.2.1-4.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gawk-4.2.1-4.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libnsl2@1.2.0-2.20180605git4a062cf.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libnsl2-1.2.0-2.20180605git4a062cf.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=ncurses-6.1-10.20180224.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=brotli-1.0.6-4.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/crypto-policies-scripts@20230731-1.git3177e06.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=crypto-policies-20230731-1.git3177e06.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/basesystem@11-5.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=basesystem-11-5.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/popt@1.18-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=popt-1.18-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libidn2@2.2.0-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libidn2-2.2.0-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/setup@2.12.2-9.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=setup-2.12.2-9.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/tzdata@2026a-1.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=tzdata-2026a-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=systemd-239-82.el8_10.15.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libxml2-2.9.7-21.el8_10.3.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/grep@3.1-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=grep-3.1-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/mpfr@3.1.6-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=mpfr-3.1.6-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/redhat-release@8.10-0.3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=redhat-release-8.10-0.3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=sqlite-3.26.0-20.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=bash-4.4.20-6.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libassuan@2.5.1-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libassuan-2.5.1-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/elfutils-libelf@0.190-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=elfutils-0.190-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgcrypt-1.8.5-7.el8_6.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/json-glib@1.4.4-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=json-glib-1.4.4-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gobject-introspection@1.56.1-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gobject-introspection-1.56.1-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gnupg2-2.2.20-4.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=glibc-2.28-251.el8_10.31.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=gcc-8.5.0-28.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libselinux@2.9-11.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libselinux-2.9-11.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gmp-6.1.2-11.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libsepol@2.9-3.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libsepol-2.9-3.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:github/actions/checkout@v4&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libgpg-error@1.31-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libgpg-error-1.31-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=rootfiles-8.1-22.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=openldap-2.4.46-21.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/info@6.5-7.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=texinfo-6.5-7.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=curl-7.61.1-34.el8_10.11.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libdb-utils@5.3.28-42.el8_4?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libdb-5.3.28-42.el8_4.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libpsl@0.20.2-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libpsl-0.20.2-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/coreutils-single@8.30-17.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=coreutils-8.30-17.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libcap-ng@0.7.11-1.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libcap-ng-0.7.11-1.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=rpm-4.14.3-32.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=cyrus-sasl-2.1.27-6.el8_5.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/crypto-policies@20230731-1.git3177e06.el8?arch=noarch&amp;distro=rhel-8.10&amp;upstream=crypto-policies-20230731-1.git3177e06.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libffi@3.1-24.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=libffi-3.1-24.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/pcre@8.42-6.el8?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=pcre-8.42-6.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/gdbm@1.18-2.el8?arch=x86_64&amp;distro=rhel-8.10&amp;epoch=1&amp;upstream=gdbm-1.18-2.el8.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/audit-libs@3.1.2-1.el8_10.1?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=audit-3.1.2-1.el8_10.1.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=lz4-1.8.3-5.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:pypi/setuptools@39.2.0&#34; : {&#xA;        &#34;concluded&#34; : {&#xA;          &#34;identifiers&#34; : [ {&#xA;            &#34;id&#34; : &#34;MIT&#34;,&#xA;            &#34;name&#34; : &#34;MIT License&#34;,&#xA;            &#34;isDeprecated&#34; : false,&#xA;            &#34;isOsiApproved&#34; : true,&#xA;            &#34;isFsfLibre&#34; : true,&#xA;            &#34;category&#34; : &#34;PERMISSIVE&#34;&#xA;          } ],&#xA;          &#34;expression&#34; : &#34;MIT&#34;,&#xA;          &#34;name&#34; : &#34;MIT License&#34;,&#xA;          &#34;category&#34; : &#34;PERMISSIVE&#34;,&#xA;          &#34;source&#34; : &#34;deps.dev&#34;,&#xA;          &#34;sourceUrl&#34; : &#34;https://api.deps.dev&#34;&#xA;        },&#xA;        &#34;evidence&#34; : [ {&#xA;          &#34;identifiers&#34; : [ {&#xA;            &#34;id&#34; : &#34;MIT&#34;,&#xA;            &#34;name&#34; : &#34;MIT License&#34;,&#xA;            &#34;isDeprecated&#34; : false,&#xA;            &#34;isOsiApproved&#34; : true,&#xA;            &#34;isFsfLibre&#34; : true,&#xA;            &#34;category&#34; : &#34;PERMISSIVE&#34;&#xA;          } ],&#xA;          &#34;expression&#34; : &#34;MIT&#34;,&#xA;          &#34;name&#34; : &#34;MIT License&#34;,&#xA;          &#34;category&#34; : &#34;PERMISSIVE&#34;,&#xA;          &#34;source&#34; : &#34;deps.dev&#34;,&#xA;          &#34;sourceUrl&#34; : &#34;https://api.deps.dev&#34;&#xA;        } ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=expat-2.5.0-1.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      },&#xA;      &#34;pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64&amp;distro=rhel-8.10&amp;upstream=util-linux-2.32.1-48.el8_10.src.rpm&#34; : {&#xA;        &#34;evidence&#34; : [ ]&#xA;      }&#xA;    }&#xA;  } ]&#xA;}&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh-tpa-scan-pod | container step-oci-attach-report: &#xA;Using token for quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;Attaching tpa-report-amd64.json to quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd@sha256:35f81c0f5e5b92451fcf6ad8d2fbbf001b6cd2964035acc1b8a84f26c5c910df&#xA;[retry] executing: oras attach --no-tty --format go-template=\{\{.digest\}\} --registry-config /tmp/auth/config.json --artifact-type application/vnd.redhat.tpa-report+json quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd@sha256:35f81c0f5e5b92451fcf6ad8d2fbbf001b6cd2964035acc1b8a84f26c5c910df tpa-report-amd64.json:application/vnd.redhat.tpa-report+json&#xA;&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-fwcsh-tpa-scan-pod | container step-conftest-vulnerabilities: &#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/tekton/home/tpa-report-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 4,&#xA;&#x9;&#x9;&#34;warnings&#34;: [&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 6 critical vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-40896, CVE-2025-49794, CVE-2025-49796), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-3596), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-15467), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32207), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-40896, CVE-2025-49794, CVE-2025-49796), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-3596)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_critical_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 6&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 115 high vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: osv-github. Affected dependencies: pkg:pypi/setuptools@39.2.0 [direct] (CVE-2024-6345, CVE-2022-40897); Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [direct] (CVE-2023-2953), pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm [direct] (CVE-2026-21945, CVE-2025-64720, CVE-2025-65018), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-6345, CVE-2025-47273), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-52425, CVE-2024-28757, CVE-2024-45490, CVE-2024-45491, CVE-2024-8176), pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtirpc-1.1.4-12.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-46828), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-6345, CVE-2025-47273), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/javapackages-filesystem@5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6?arch=noarch\u0026distro=rhel-8.10\u0026upstream=javapackages-tools-5.3.0-1.module%2Bel8%2B2447%2B6f56d9a6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-48734, CVE-2019-10086), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-40217, CVE-2022-42919, CVE-2023-6597, CVE-2015-20107, CVE-2024-12718, CVE-2025-4517, CVE-2020-10735, CVE-2022-45061, CVE-2023-24329, CVE-2024-6232, CVE-2025-12084, CVE-2025-4138, CVE-2025-4435, CVE-2025-8194, CVE-2021-28861, CVE-2025-4330, CVE-2025-15366, CVE-2025-15367, CVE-2026-1299, CVE-2026-4519), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=cups-2.2.6-67.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-58060, CVE-2024-47175, CVE-2023-34241), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-52425, CVE-2024-28757, CVE-2024-45490, CVE-2024-45491, CVE-2024-8176), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-2509, CVE-2024-0553, CVE-2024-0567, CVE-2023-0361), pkg:rpm/redhat/libtirpc@1.1.4-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtirpc-1.1.4-12.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-46828), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-44964), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2025-15079, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-56171, CVE-2022-40304, CVE-2025-24928, CVE-2025-7425, CVE-2022-40303, CVE-2024-25062, CVE-2025-32415, CVE-2025-49795, CVE-2025-6021, CVE-2025-7424, CVE-2022-29824), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-5914, CVE-2026-4111, CVE-2026-4424, CVE-2026-5121), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-44487, CVE-2026-27135), pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=brotli-1.0.6-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6176), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2953), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1473, CVE-2022-3358, CVE-2022-3602, CVE-2022-3786, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-5363, CVE-2023-0286, CVE-2024-12797, CVE-2025-69419), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-22576, CVE-2023-38545, CVE-2025-15079, CVE-2022-27775, CVE-2022-27782, CVE-2024-2398), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-56171, CVE-2022-40304, CVE-2025-24928, CVE-2025-7425, CVE-2022-40303, CVE-2024-25062, CVE-2025-32415, CVE-2025-49795, CVE-2025-6021, CVE-2025-7424, CVE-2022-29824), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-42898, CVE-2023-39975, CVE-2024-26462, CVE-2024-37370, CVE-2020-17049), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=xz-5.2.4-4.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1271, CVE-2025-31115), pkg:rpm/redhat/libksba@1.3.5-9.el8_7?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libksba-1.3.5-9.el8_7.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-3515, CVE-2022-47629), pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnupg2-2.2.20-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2026-24882, CVE-2025-68973), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5318, CVE-2025-5987), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-5914, CVE-2026-4111, CVE-2026-4424, CVE-2026-5121), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-13601, CVE-2024-52533), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6965, CVE-2023-7104, CVE-2025-3277), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-33928, CVE-2021-33929, CVE-2021-33930, CVE-2021-33938, CVE-2021-46877), pkg:rpm/redhat/brotli@1.0.6-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=brotli-1.0.6-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6176), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-2509, CVE-2024-0553, CVE-2024-0567, CVE-2023-0361), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-44487, CVE-2026-27135), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2953), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/zlib@1.2.11-25.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=zlib-1.2.11-25.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2018-25032, CVE-2022-37434), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2024-2961, CVE-2026-0861, CVE-2023-4911, CVE-2024-33599, CVE-2025-4802), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-2603), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-29491, CVE-2025-69720), pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=pcre2-10.32-3.el8_6.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-1586, CVE-2022-1587)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_high_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 115&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 185 medium vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm [direct] (CVE-2026-21933, CVE-2026-21925), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [direct] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm [direct] (CVE-2025-45582, CVE-2022-48303), pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm [direct] (CVE-2023-4641), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-40897), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-45492, CVE-2024-50602, CVE-2025-59375), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-pip-9.0.3-24.el8.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2007-4559), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-9.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-setuptools-39.2.0-9.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-40897), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-6923, CVE-2025-0938, CVE-2025-13836, CVE-2024-9287, CVE-2024-0450, CVE-2007-4559, CVE-2023-27043, CVE-2024-8088, CVE-2024-0397, CVE-2024-7592, CVE-2026-0865, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075), pkg:rpm/redhat/cups-libs@2.2.6-67.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=cups-2.2.6-67.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-26691, CVE-2023-32360, CVE-2025-58364, CVE-2023-32324, CVE-2025-58436, CVE-2024-35235), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/expat@2.5.0-1.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=expat-2.5.0-1.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-45492, CVE-2024-50602, CVE-2025-59375), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-32988, CVE-2025-32990, CVE-2025-6395, CVE-2023-5981, CVE-2024-12243, CVE-2024-28834, CVE-2025-14831, CVE-2025-32989, CVE-2024-28835, CVE-2025-9820), pkg:rpm/redhat/lua@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/dbus-libs@1.12.8-27.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=dbus-1.12.8-27.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-42010, CVE-2022-42011, CVE-2022-42012, CVE-2023-34969), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519, CVE-2021-44964), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/avahi-libs@0.7-27.el8_10.1?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=avahi-0.7-27.el8_10.1.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-3468, CVE-2023-1981, CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473, CVE-2021-3502, CVE-2024-52615, CVE-2024-52616), pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104, CVE-2026-27456), pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=systemd-239-82.el8_10.15.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-7008, CVE-2022-3821, CVE-2022-4415, CVE-2022-45873, CVE-2025-4598), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2236), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=python-pip-9.0.3-24.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2007-4559), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/alsa-lib@1.2.10-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=alsa-lib-1.2.10-2.el8.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2026-25068), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-32206, CVE-2023-23916, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-13034, CVE-2025-14819, CVE-2026-1965, CVE-2022-32206, CVE-2023-23916, CVE-2025-14524, CVE-2026-3784, CVE-2026-3805, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2025-10966, CVE-2026-3783, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2025-10148, CVE-2025-14017, CVE-2025-15224, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-39615, CVE-2025-9714, CVE-2022-49043, CVE-2023-28484, CVE-2023-29469, CVE-2025-32414, CVE-2025-26434), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-48795, CVE-2026-3731, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-48795, CVE-2026-3731, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-26280, CVE-2022-36227, CVE-2025-60753, CVE-2024-57970, CVE-2025-25724), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-28182), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519, CVE-2021-44964), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1292, CVE-2022-2068, CVE-2023-2650, CVE-2023-6129, CVE-2025-69421, CVE-2025-11187, CVE-2020-1971, CVE-2022-4304, CVE-2023-0464, CVE-2023-6237, CVE-2024-5535, CVE-2024-6119, CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, CVE-2026-22796, CVE-2024-4741, CVE-2025-9230, CVE-2024-0727, CVE-2025-15469, CVE-2026-22795, CVE-2022-1343, CVE-2022-2097, CVE-2023-0465, CVE-2023-0466, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-5678, CVE-2024-4603, CVE-2023-1255, CVE-2022-4203, CVE-2025-68160, CVE-2025-69418), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-32206, CVE-2023-23916, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-13034, CVE-2025-14819, CVE-2026-1965, CVE-2022-32206, CVE-2023-23916, CVE-2025-14524, CVE-2026-3784, CVE-2026-3805, CVE-2022-43552, CVE-2023-27535, CVE-2023-27536, CVE-2023-28321, CVE-2025-10966, CVE-2026-3783, CVE-2023-27538, CVE-2022-32208, CVE-2023-46218, CVE-2025-9086, CVE-2022-27774, CVE-2022-32221, CVE-2025-10148, CVE-2025-14017, CVE-2025-15224, CVE-2022-27776, CVE-2023-27533), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-39615, CVE-2025-9714, CVE-2022-49043, CVE-2023-28484, CVE-2023-29469, CVE-2025-32414, CVE-2025-26434), pkg:rpm/redhat/krb5-libs@1.18.2-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=krb5-1.18.2-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-36054, CVE-2024-37371, CVE-2025-24528, CVE-2024-26458, CVE-2024-26461, CVE-2025-3576), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/gnupg2@2.2.20-4.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnupg2-2.2.20-4.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-34903, CVE-2025-68972), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-48795, CVE-2026-3731, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-48795, CVE-2026-3731, CVE-2023-2283, CVE-2023-6004, CVE-2023-1667), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/libarchive@3.3.3-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libarchive-3.3.3-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-26280, CVE-2022-36227, CVE-2025-60753, CVE-2024-57970, CVE-2025-25724), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-32611, CVE-2023-32665, CVE-2025-14512, CVE-2023-29499, CVE-2025-14087, CVE-2025-4373), pkg:rpm/redhat/sqlite-libs@3.26.0-20.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=sqlite-3.26.0-20.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-35737), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-28863, CVE-2021-44568), pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.5?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gnutls-3.6.16-8.el8_10.5.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-32988, CVE-2025-32990, CVE-2025-6395, CVE-2023-5981, CVE-2024-12243, CVE-2024-28834, CVE-2025-14831, CVE-2025-32989, CVE-2024-28835, CVE-2025-9820), pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.2?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=nghttp2-1.33.0-6.el8_10.2.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-28182), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/lua-libs@5.3.4-12.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lua-5.3.4-12.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-33099, CVE-2022-28805, CVE-2021-43519, CVE-2021-44964), pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-35938, CVE-2021-35939, CVE-2021-35937), pkg:rpm/redhat/gmp@6.1.2-11.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=gmp-6.1.2-11.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-43618), pkg:rpm/redhat/libsmartcols@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libmount@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libuuid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104), pkg:rpm/redhat/libblkid@2.32.1-48.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=util-linux-2.32.1-48.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-14104, CVE-2026-27456), pkg:rpm/redhat/libstdc%2B%2B@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libtasn1-4.13-5.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-46848, CVE-2025-13151, CVE-2024-12133), pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2236), pkg:rpm/redhat/systemd-libs@239-82.el8_10.15?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=systemd-239-82.el8_10.15.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-7008, CVE-2022-3821, CVE-2022-4415, CVE-2022-45873, CVE-2025-4598), pkg:rpm/redhat/libcom_err@1.45.6-7.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=e2fsprogs-1.45.6-7.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-1304), pkg:rpm/redhat/file-libs@5.33-27.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=file-5.33-27.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2022-48554), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/tar@1.30-11.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=tar-1.30-11.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/lz4-libs@1.8.3-5.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=lz4-1.8.3-5.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/rootfiles@8.1-22.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=rootfiles-8.1-22.el8.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/libsemanage@2.9-12.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsemanage-2.9-12.el8_10.src.rpm] (CVE-2019-12900), pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-15281, CVE-2026-3904, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/glibc-common@2.28-251.el8_10.31?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glibc-2.28-251.el8_10.31.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-4527, CVE-2023-4806, CVE-2023-4813, CVE-2025-5702, CVE-2025-0395, CVE-2024-33600, CVE-2026-0915, CVE-2025-8058, CVE-2024-33601, CVE-2024-33602), pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=ncurses-6.1-10.20180224.el8.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-29458), pkg:rpm/redhat/bash@4.4.20-6.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bash-4.4.20-6.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2022-3715), pkg:rpm/redhat/libgcc@8.5.0-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=gcc-8.5.0-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2020-11023), pkg:rpm/redhat/bzip2-libs@1.0.6-28.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=bzip2-1.0.6-28.el8_10.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2019-12900)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_medium_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 185&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;{&#xA;&#x9;&#x9;&#x9;&#x9;&#34;msg&#34;: &#34;Found 14 low vulnerabilities.&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#34;metadata&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;details&#34;: {&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;description&#34;: &#34;Source: redhat-csaf. Affected dependencies: pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [direct] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm [direct] (CVE-2024-56433), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/openldap@2.4.46-21.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=openldap-2.4.46-21.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/python3-libs@3.6.8-75.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=python3-3.6.8-75.el8_10.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2024-11168, CVE-2024-4032, CVE-2024-5642), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/java-17-openjdk-headless@17.0.18.0.8-1.el8?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=java-17-openjdk-17.0.18.0.8-1.el8.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2025-6170), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=rpm-4.14.3-32.el8_10.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/openssl-libs@1.1.1k-15.el8_6?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=1\u0026upstream=openssl-1.1.1k-15.el8_6.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-2511), pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/curl@7.61.1-34.el8_10.11?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=curl-7.61.1-34.el8_10.11.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-27534, CVE-2023-28322, CVE-2023-38546, CVE-2022-35252), pkg:rpm/redhat/libxml2@2.9.7-21.el8_10.3?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libxml2-2.9.7-21.el8_10.3.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2025-6170), pkg:rpm/redhat/libssh-config@0.9.6-16.el8_10?arch=noarch\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libssh@0.9.6-16.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libssh-0.9.6-16.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-6918), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2023-2602), pkg:rpm/redhat/glib2@2.56.4-168.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=glib2-2.56.4-168.el8_10.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2024-34397), pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libsolv-0.7.20-6.el8.src.rpm [transitive via pkg:rpm/redhat/microdnf@3.8.0-2.el8?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=microdnf-3.8.0-2.el8.src.rpm] (CVE-2021-3200), pkg:rpm/redhat/libcap@2.48-6.el8_9?arch=x86_64\u0026distro=rhel-8.10\u0026upstream=libcap-2.48-6.el8_9.src.rpm [transitive via pkg:rpm/redhat/shadow-utils@4.6-23.el8_10?arch=x86_64\u0026distro=rhel-8.10\u0026epoch=2\u0026upstream=shadow-utils-4.6-23.el8_10.src.rpm] (CVE-2023-2602)&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;name&#34;: &#34;rhtpa_low_vulnerabilities&#34;,&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;url&#34;: &#34;https://access.redhat.com/articles/red_hat_vulnerability_tutorial&#34;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;},&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&#34;vulnerabilities_number&#34;: 14&#xA;&#x9;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;&#x9;}&#xA;&#x9;&#x9;]&#xA;&#x9;}&#xA;]&#xA;{&#34;vulnerabilities&#34;:{&#34;critical&#34;:6,&#34;high&#34;:115,&#34;medium&#34;:185,&#34;low&#34;:14,&#34;unknown&#34;:0},&#34;unpatched_vulnerabilities&#34;:{&#34;critical&#34;:0,&#34;high&#34;:0,&#34;medium&#34;:0,&#34;low&#34;:0,&#34;unknown&#34;:0}}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd:on-pr-4d2226c5919fd71f93701057ce59fa8f2bad3ae6&#34;, &#34;digests&#34;: [&#34;sha256:35f81c0f5e5b92451fcf6ad8d2fbbf001b6cd2964035acc1b8a84f26c5c910df&#34;]}}&#xA;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T14:10:35+00:00&#34;,&#34;note&#34;:&#34;Task tpa-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by TPA.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;New PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d found after retrigger for component forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d found for Component forgejo-rep-xlpn/test-comp-pac-forgejo-wqnvvd&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Running&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: PipelineRunStopping&#xA;PipelineRun test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d reason: Failed&#xA;attempt 3/3: PipelineRun &#34;test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d&#34; failed: &#xA; pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | init container: prepare&#xA;2026/04/22 14:14:24 Entrypoint initialization&#xA;&#xA;pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | container step-init: &#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;[FAILED] Expected success, but got an error:&#xA;    &lt;*errors.errorString | 0xc0015450d0&gt;: &#xA;    &#xA;     pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | init container: prepare&#xA;    2026/04/22 14:14:24 Entrypoint initialization&#xA;    &#xA;    pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | container step-init: &#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;    time=&#34;2026-04-22T14:14:27Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;    &#xA;    {&#xA;        s: &#34;\n pod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | init container: prepare\n2026/04/22 14:14:24 Entrypoint initialization\n\npod: test-comp-pac-forgejo-wqnvvd-on-pull-request-p668d-init-pod | container step-init: \ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;Using in-cluster config\&#34; logger=KubeClient\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] enable: false\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] http-proxy-result-path: /tekton/results/http-proxy\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[param] no-proxy-result-path: /tekton/results/no-proxy\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;Cache proxy is disabled in param or in backend\&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[result] HTTP PROXY: \&#34;\ntime=\&#34;2026-04-22T14:14:27Z\&#34; level=info msg=\&#34;[result] NO PROXY: \&#34;\n&#34;,&#xA;    }&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:179 @ 04/22/26 14:22:44.204&#xA;&lt; Exit [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:177 @ 04/22/26 14:22:44.204 (29m54.215s)&#xA;&gt; Enter [AfterAll] Forgejo with status reporting of Integration tests in the associated merge request - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:96 @ 04/22/26 14:22:44.204&#xA;&lt; Exit [AfterAll] Forgejo with status reporting of Integration tests in the associated merge request - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:96 @ 04/22/26 14:22:44.207 (4ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:45 @ 04/22/26 14:22:44.208&#xA;&lt; Exit [AfterEach] [integration-service-suite Forgejo Status Reporting of Integration tests] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:45 @ 04/22/26 14:22:44.323 (116ms)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created should have a related PaC init MR created [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:182 @ 04/22/26 14:22:44.339&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when a new Component with specified custom branch is created the PipelineRun should eventually finish successfully for component  [integration-service, forgejo-status-reporting, custom-branch]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:201 @ 04/22/26 14:22:44.34&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when the PaC build pipelineRun run succeeded checks if the BuildPipelineRun has the annotation of chains signed [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:208 @ 04/22/26 14:22:44.34&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when the PaC build pipelineRun run succeeded checks if the Snapshot is created [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:212 @ 04/22/26 14:22:44.34&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when the PaC build pipelineRun run succeeded checks if the Build PipelineRun got annotated with Snapshot name [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:217 @ 04/22/26 14:22:44.34&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when the Snapshot was created should find the Integration Test Scenario PipelineRun [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:223 @ 04/22/26 14:22:44.341&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created should eventually complete successfully [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:232 @ 04/22/26 14:22:44.341&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:237 @ 04/22/26 14:22:44.341&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created validates at least one MR comment contains the final integration test result [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:243 @ 04/22/26 14:22:44.341&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created merging the PR should be successful [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:272 @ 04/22/26 14:22:44.341&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Integration PipelineRun is created leads to triggering a push PipelineRun [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:287 @ 04/22/26 14:22:44.342&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Run integration tests after Merged MR should eventually complete successfully [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:304 @ 04/22/26 14:22:44.342&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Forgejo Status Reporting of Integration tests] Forgejo with status reporting of Integration tests in the associated merge request when Run integration tests after Merged MR eventually leads to the integration test PipelineRun&#39;s Pass status reported at MR commit status [integration-service, forgejo-status-reporting]" classname="Red Hat App Studio E2E tests" status="skipped" time="0">
              <skipped message="skipped - Spec skipped because an earlier spec in an ordered container failed"></skipped>
              <system-err>[SKIPPED] Spec skipped because an earlier spec in an ordered container failed&#xA;In [It] at: /tmp/tmp.QN7KPSPXeP/tests/integration-service/forgejo-integration-reporting.go:309 @ 04/22/26 14:22:44.342&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A creates the Component A successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="15.713250271">
              <system-err>&gt; Enter [BeforeAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:60 @ 04/22/26 13:50:09.893&#xA;Successfully acquired repository lock for namespace group-psuf&#xA;&lt; Exit [BeforeAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:60 @ 04/22/26 13:50:15.576 (5.683s)&#xA;&gt; Enter [It] creates the Component A successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:205 @ 04/22/26 13:50:15.576&#xA;&lt; Exit [It] creates the Component A successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:205 @ 04/22/26 13:50:25.603 (10.027s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 13:50:25.603&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 13:50:25.603 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A triggers a Build PipelineRun for componentA go-component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="40.034350338">
              <system-err>&gt; Enter [It] triggers a Build PipelineRun for componentA go-component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:213 @ 04/22/26 13:50:25.604&#xA;Build PipelineRun has not been created yet for the componentA group-psuf/go-component-opambg&#xA;Build PipelineRun has not been created yet for the componentA group-psuf/go-component-opambg&#xA;&lt; Exit [It] triggers a Build PipelineRun for componentA go-component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:213 @ 04/22/26 13:51:05.638 (40.034s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 13:51:05.638&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 13:51:05.638 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A does not contain an annotation with a Snapshot Name [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.000244415">
              <system-err>&gt; Enter [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:227 @ 04/22/26 13:51:05.639&#xA;&lt; Exit [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:227 @ 04/22/26 13:51:05.639 (0s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 13:51:05.639&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 13:51:05.639 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A should lead to build PipelineRunA finishing successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="754.814414635">
              <system-err>&gt; Enter [It] should lead to build PipelineRunA finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:231 @ 04/22/26 13:51:05.639&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 found for Component group-psuf/go-component-opambg&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: ResolvingTaskRef&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: PipelineRunStopping&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: PipelineRunStopping&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: PipelineRunStopping&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: PipelineRunStopping&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: PipelineRunStopping&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: PipelineRunStopping&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: PipelineRunStopping&#xA;PipelineRun go-component-opambg-on-pull-request-swzc5 reason: Failed&#xA;attempt 1/3: PipelineRun &#34;go-component-opambg-on-pull-request-swzc5&#34; failed: &#xA; pod: go-component-opambg-on-pull-request-swzc5-apply-tags-pod | init container: prepare&#xA;2026/04/22 13:54:39 Entrypoint initialization&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-apply-tags-pod | container step-apply-additional-tags: &#xA;time=&#34;2026-04-22T13:54:41Z&#34; level=info msg=&#34;[param] image-url: quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;&#xA;time=&#34;2026-04-22T13:54:41Z&#34; level=info msg=&#34;[param] digest: sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#34;&#xA;time=&#34;2026-04-22T13:54:41Z&#34; level=info msg=&#34;[param] tags-from-image-label: konflux.additional-tags&#34;&#xA;time=&#34;2026-04-22T13:54:42Z&#34; level=warning msg=&#34;No tags given in &#39;konflux.additional-tags&#39; image label&#34;&#xA;{&#34;tags&#34;:[]}&#xA; pod: go-component-opambg-on-pull-request-swzc5-build-container-pod | init container: prepare&#xA;2026/04/22 13:51:45 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-build-container-pod | init container: place-scripts&#xA;2026/04/22 13:51:45 Decoded script /tekton/scripts/script-0-f4f2n&#xA;2026/04/22 13:51:45 Decoded script /tekton/scripts/script-1-8bqs2&#xA;2026/04/22 13:51:45 Decoded script /tekton/scripts/script-2-dzvhp&#xA;2026/04/22 13:51:45 Decoded script /tekton/scripts/script-3-d7h45&#xA;2026/04/22 13:51:45 Decoded script /tekton/scripts/script-4-mzzrd&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-build-container-pod | init container: working-dir-initializer&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-build-container-pod | container step-build: &#xA;[2026-04-22T13:52:18,640427312+00:00] Validate context path&#xA;[2026-04-22T13:52:18,643747844+00:00] Update CA trust&#xA;[2026-04-22T13:52:18,644790049+00:00] Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;[2026-04-22T13:52:20,656199609+00:00] Prepare Dockerfile&#xA;Checking if /var/workdir/cachi2/output/bom.json exists.&#xA;Could not find prefetched sbom. No content_sets found for ICM&#xA;[2026-04-22T13:52:20,661783146+00:00] Prepare system (architecture: x86_64)&#xA;[2026-04-22T13:52:20,673596916+00:00] Setup prefetched&#xA;Trying to pull registry.access.redhat.com/ubi9/go-toolset:1.18.9-14...&#xA;Getting image source signatures&#xA;Checking if image destination supports signatures&#xA;Copying blob sha256:e76793d6902ad1adb19ede3d720024cf0cd8427b3ff606554a4bcafba03dddf4&#xA;Copying blob sha256:0ab0ba77295aca9b12f463cb7198f0b8b6990b41151dbbd4e1b224fe85244b83&#xA;Copying blob sha256:4a13c0e9217d70e608f2d5f5d3c5ffa6d9cd16908b3f83a7a97492d355d25a09&#xA;Copying blob sha256:2a625e4afab51b49edb0e5f4ff37d8afbb20ec644ed1e68641358a6305557de3&#xA;Copying config sha256:391a2eac28d98dc72726df1faa77db28f6899a77c91ad40f2bdad62baf041301&#xA;Writing manifest to image destination&#xA;Storing signatures&#xA;[2026-04-22T13:53:02,370505460+00:00] Unsetting proxy&#xA;{&#xA;  &#34;architecture&#34;: &#34;x86_64&#34;,&#xA;  &#34;build-date&#34;: &#34;2026-04-22T13:52:20Z&#34;,&#xA;  &#34;com.redhat.component&#34;: &#34;go-toolset-container&#34;,&#xA;  &#34;com.redhat.license_terms&#34;: &#34;https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI&#34;,&#xA;  &#34;description&#34;: &#34;Go Toolset available as a container is a base platform for building and running various Go applications and frameworks. Go is an easy to learn, powerful, statically typed language in the C/C++ tradition with garbage collection, concurrent programming support, and memory safety features.&#34;,&#xA;  &#34;distribution-scope&#34;: &#34;public&#34;,&#xA;  &#34;io.buildah.version&#34;: &#34;1.42.2&#34;,&#xA;  &#34;io.k8s.description&#34;: &#34;Go Toolset available as a container is a base platform for building and running various Go applications and frameworks. Go is an easy to learn, powerful, statically typed language in the C/C++ tradition with garbage collection, concurrent programming support, and memory safety features.&#34;,&#xA;  &#34;io.k8s.display-name&#34;: &#34;Go 1.18.9&#34;,&#xA;  &#34;io.openshift.expose-services&#34;: &#34;&#34;,&#xA;  &#34;io.openshift.s2i.scripts-url&#34;: &#34;image:///usr/libexec/s2i&#34;,&#xA;  &#34;io.openshift.tags&#34;: &#34;builder,golang,golang118,rh-golang118,go&#34;,&#xA;  &#34;io.s2i.scripts-url&#34;: &#34;image:///usr/libexec/s2i&#34;,&#xA;  &#34;maintainer&#34;: &#34;Red Hat, Inc.&#34;,&#xA;  &#34;name&#34;: &#34;rhel9/go-toolset&#34;,&#xA;  &#34;release&#34;: &#34;14&#34;,&#xA;  &#34;summary&#34;: &#34;Platform for building and running Go Applications&#34;,&#xA;  &#34;url&#34;: &#34;https://access.redhat.com/containers/#/registry.access.redhat.com/rhel9/go-toolset/images/1.18.9-14&#34;,&#xA;  &#34;vcs-ref&#34;: &#34;4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;,&#xA;  &#34;vcs-type&#34;: &#34;git&#34;,&#xA;  &#34;vendor&#34;: &#34;Red Hat, Inc.&#34;,&#xA;  &#34;version&#34;: &#34;1.18.9&#34;,&#xA;  &#34;org.opencontainers.image.revision&#34;: &#34;4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;,&#xA;  &#34;org.opencontainers.image.source&#34;: &#34;https://github.com/redhat-appstudio-qe/group-snapshot-multi-component&#34;,&#xA;  &#34;quay.expires-after&#34;: &#34;6h&#34;,&#xA;  &#34;org.opencontainers.image.created&#34;: &#34;2026-04-22T13:52:20Z&#34;&#xA;}&#xA;[2026-04-22T13:53:02,414596843+00:00] Register sub-man&#xA;Adding the entitlement to the build&#xA;[2026-04-22T13:53:02,417763957+00:00] Add secrets&#xA;[2026-04-22T13:53:02,425014482+00:00] Run buildah build&#xA;[2026-04-22T13:53:02,426070611+00:00] buildah build --volume /tmp/entitlement:/etc/pki/entitlement --security-opt=unmask=/proc/interrupts --label architecture=x86_64 --label vcs-type=git --label vcs-ref=4d756f25691014cb931c9ba1a2acbdad0b590a3e --label org.opencontainers.image.revision=4d756f25691014cb931c9ba1a2acbdad0b590a3e --label org.opencontainers.image.source=https://github.com/redhat-appstudio-qe/group-snapshot-multi-component --label quay.expires-after=6h --label build-date=2026-04-22T13:52:20Z --label org.opencontainers.image.created=2026-04-22T13:52:20Z --annotation org.opencontainers.image.revision=4d756f25691014cb931c9ba1a2acbdad0b590a3e --annotation org.opencontainers.image.source=https://github.com/redhat-appstudio-qe/group-snapshot-multi-component --annotation org.opencontainers.image.created=2026-04-22T13:52:20Z --tls-verify=true --no-cache --ulimit nofile=4096:4096 --http-proxy=false -f /tmp/Dockerfile.Baaml2 -t quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e . &#xA;STEP 1/10: FROM registry.access.redhat.com/ubi9/go-toolset:1.18.9-14&#xA;STEP 2/10: COPY . .&#xA;STEP 3/10: RUN go mod download&#xA;go: no module dependencies to download&#xA;STEP 4/10: RUN go build -o ./main&#xA;STEP 5/10: ENV PORT 8081&#xA;STEP 6/10: EXPOSE 8081&#xA;STEP 7/10: CMD [ &#34;./main&#34; ]&#xA;STEP 8/10: COPY labels.json /usr/share/buildinfo/labels.json&#xA;STEP 9/10: COPY labels.json /root/buildinfo/labels.json&#xA;STEP 10/10: LABEL &#34;architecture&#34;=&#34;x86_64&#34; &#34;vcs-type&#34;=&#34;git&#34; &#34;vcs-ref&#34;=&#34;4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34; &#34;org.opencontainers.image.revision&#34;=&#34;4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34; &#34;org.opencontainers.image.source&#34;=&#34;https://github.com/redhat-appstudio-qe/group-snapshot-multi-component&#34; &#34;quay.expires-after&#34;=&#34;6h&#34; &#34;build-date&#34;=&#34;2026-04-22T13:52:20Z&#34; &#34;org.opencontainers.image.created&#34;=&#34;2026-04-22T13:52:20Z&#34;&#xA;COMMIT quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;--&gt; 1da500647b06&#xA;Successfully tagged quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;1da500647b06f5114eea3e0c7bc82ff2687b5a22e0652def72aae7927be04264&#xA;[2026-04-22T13:53:05,388315087+00:00] Unsetting proxy&#xA;[2026-04-22T13:53:05,389491816+00:00] Add metadata&#xA;Recording base image digests used&#xA;registry.access.redhat.com/ubi9/go-toolset:1.18.9-14 registry.access.redhat.com/ubi9/go-toolset:1.18.9-14@sha256:4e320bd8b62e406dfc567886aeab4914db125c73fe9ec308b306c72883101d51&#xA;Getting image source signatures&#xA;Copying blob sha256:5bdd2c12e5754378855f66ad1510599fd09d350d8f8cc1e961ba02a725c53069&#xA;Copying blob sha256:d3f6a420cbadfb30033dc481690b39191ce6d2d841ccd54434c352f474ea54c3&#xA;Copying blob sha256:314640f419c581ddcac8f3618af39342a4571d5dc7a4e1f5b64d60f37e630b49&#xA;Copying blob sha256:db77b3de17313a3fab2620178c01a4ef8eb60cbe722a6e9390f3cbb1132a7d22&#xA;Copying blob sha256:a653a5ff4eaef6037f4f354414ab251ac7218d2d42fc8326743fc63ecf2cabd5&#xA;Copying config sha256:1da500647b06f5114eea3e0c7bc82ff2687b5a22e0652def72aae7927be04264&#xA;Writing manifest to image destination&#xA;[2026-04-22T13:53:12,912873561+00:00] End build&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-build-container-pod | container step-push: &#xA;[2026-04-22T13:53:13,745352681+00:00] Update CA trust&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;[2026-04-22T13:53:15,795893612+00:00] Convert image&#xA;[2026-04-22T13:53:15,796943776+00:00] Push image with unique tag&#xA;Pushing to quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:go-component-opambg-on-pull-request-swzc5-build-container&#xA;[retry] executing: buildah push --format=docker --retry 3 --tls-verify=true quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e docker://quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:go-component-opambg-on-pull-request-swzc5-build-container&#xA;Getting image source signatures&#xA;Copying blob sha256:5bdd2c12e5754378855f66ad1510599fd09d350d8f8cc1e961ba02a725c53069&#xA;Copying blob sha256:d3f6a420cbadfb30033dc481690b39191ce6d2d841ccd54434c352f474ea54c3&#xA;Copying blob sha256:314640f419c581ddcac8f3618af39342a4571d5dc7a4e1f5b64d60f37e630b49&#xA;Copying blob sha256:a653a5ff4eaef6037f4f354414ab251ac7218d2d42fc8326743fc63ecf2cabd5&#xA;Copying blob sha256:db77b3de17313a3fab2620178c01a4ef8eb60cbe722a6e9390f3cbb1132a7d22&#xA;Copying config sha256:1da500647b06f5114eea3e0c7bc82ff2687b5a22e0652def72aae7927be04264&#xA;Writing manifest to image destination&#xA;[2026-04-22T13:53:30,411844991+00:00] Push image with git revision&#xA;Pushing to quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;[retry] executing: buildah push --format=docker --retry 3 --tls-verify=true --digestfile /workspace/source/image-digest quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e docker://quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;Getting image source signatures&#xA;Copying blob sha256:314640f419c581ddcac8f3618af39342a4571d5dc7a4e1f5b64d60f37e630b49&#xA;Copying blob sha256:d3f6a420cbadfb30033dc481690b39191ce6d2d841ccd54434c352f474ea54c3&#xA;Copying blob sha256:a653a5ff4eaef6037f4f354414ab251ac7218d2d42fc8326743fc63ecf2cabd5&#xA;Copying blob sha256:5bdd2c12e5754378855f66ad1510599fd09d350d8f8cc1e961ba02a725c53069&#xA;Copying blob sha256:db77b3de17313a3fab2620178c01a4ef8eb60cbe722a6e9390f3cbb1132a7d22&#xA;Copying config sha256:1da500647b06f5114eea3e0c7bc82ff2687b5a22e0652def72aae7927be04264&#xA;Writing manifest to image destination&#xA;sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;[retry] executing: kubectl get configmap cluster-config -n konflux-info -o json&#xA;Keyless signing is disabled (none of rekorInternalUrl, fulcioInternalUrl, defaultOIDCIssuer, tufInternalUrl are configured in the konflux-info/cluster-config configmap)&#xA;[2026-04-22T13:53:31,230417548+00:00] End push&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-build-container-pod | container step-sbom-syft-generate: &#xA;[2026-04-22T13:53:31,890197977+00:00] Generate SBOM&#xA;Running syft on the image&#xA;Running syft on the source code&#xA;[0000]  WARN no explicit name and version provided for directory source, deriving artifact ID from the given path (which is not ideal)&#xA;[2026-04-22T13:53:52,616110062+00:00] End sbom-syft-generate&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-build-container-pod | container step-prepare-sboms: &#xA;[2026-04-22T13:53:53,234843704+00:00] Prepare SBOM&#xA;[2026-04-22T13:53:53,238893687+00:00] Generate SBOM with mobster&#xA;Skipping SBOM validation&#xA;2026-04-22 13:53:54,315 [INFO] mobster.log: Logging level set to 20&#xA;2026-04-22 13:53:54,749 [INFO] mobster.oci: Fetching manifest for registry.access.redhat.com/ubi9/go-toolset@sha256:4e320bd8b62e406dfc567886aeab4914db125c73fe9ec308b306c72883101d51&#xA;2026-04-22 13:53:55,231 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type spdxjson failed for registry.access.redhat.com/ubi9/go-toolset@sha256:0200988bf4773dad494d97be5aeceb005da3b329fe6827c035509a3f6eec1ef1 with output b&#39;Error: found no attestations\nerror during command execution: found no attestations\n&#39;&#xA;2026-04-22 13:53:55,354 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type cyclonedx failed for registry.access.redhat.com/ubi9/go-toolset@sha256:0200988bf4773dad494d97be5aeceb005da3b329fe6827c035509a3f6eec1ef1 with output b&#39;Error: found no attestations\nerror during command execution: found no attestations\n&#39;&#xA;2026-04-22 13:53:55,672 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type spdxjson failed for registry.access.redhat.com/ubi9/go-toolset@sha256:0200988bf4773dad494d97be5aeceb005da3b329fe6827c035509a3f6eec1ef1 with output b&#39;Error: found no attestations\nerror during command execution: found no attestations\n&#39;&#xA;2026-04-22 13:53:55,785 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type cyclonedx failed for registry.access.redhat.com/ubi9/go-toolset@sha256:0200988bf4773dad494d97be5aeceb005da3b329fe6827c035509a3f6eec1ef1 with output b&#39;Error: found no attestations\nerror during command execution: found no attestations\n&#39;&#xA;2026-04-22 13:53:56,100 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type spdxjson failed for registry.access.redhat.com/ubi9/go-toolset@sha256:0200988bf4773dad494d97be5aeceb005da3b329fe6827c035509a3f6eec1ef1 with output b&#39;Error: found no attestations\nerror during command execution: found no attestations\n&#39;&#xA;2026-04-22 13:53:56,204 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type cyclonedx failed for registry.access.redhat.com/ubi9/go-toolset@sha256:0200988bf4773dad494d97be5aeceb005da3b329fe6827c035509a3f6eec1ef1 with output b&#39;Error: found no attestations\nerror during command execution: found no attestations\n&#39;&#xA;2026-04-22 13:53:56,561 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type spdxjson failed for registry.access.redhat.com/ubi9/go-toolset@sha256:0200988bf4773dad494d97be5aeceb005da3b329fe6827c035509a3f6eec1ef1 with output b&#39;Error: found no attestations\nerror during command execution: found no attestations\n&#39;&#xA;2026-04-22 13:53:56,679 [WARNING] mobster.oci.cosign.anonymous_fetcher: Cosign fetching attestation of type cyclonedx failed for registry.access.redhat.com/ubi9/go-toolset@sha256:0200988bf4773dad494d97be5aeceb005da3b329fe6827c035509a3f6eec1ef1 with output b&#39;Error: found no attestations\nerror during command execution: found no attestations\n&#39;&#xA;2026-04-22 13:53:56,679 [INFO] mobster.cmd.generate.oci_image.contextual_sbom.contextualize: Contextual mechanism won&#39;t be used, there is no parent image SBOM.&#xA;2026-04-22 13:53:56,679 [INFO] mobster.cmd.generate.oci_image: Contextual SBOM workflow finished successfully.&#xA;2026-04-22 13:53:56,681 [INFO] mobster.log: Contextual workflow completed in 2.03s&#xA;2026-04-22 13:53:56,834 [INFO] mobster.main: Exiting with code 0.&#xA;[2026-04-22T13:53:56,901596756+00:00] End prepare-sboms&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-build-container-pod | container step-upload-sbom: &#xA;[2026-04-22T13:53:57,299992023+00:00] Upload SBOM&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;Using token for quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg&#xA;Pushing sbom to registry&#xA;[retry] executing: cosign attach sbom --sbom sbom.json --type spdx quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#xA;WARNING: SBOM attachments are deprecated and support will be removed in a Cosign release soon after 2024-02-22 (see https://github.com/sigstore/cosign/issues/2755). Instead, please use SBOM attestations.&#xA;WARNING: Attaching SBOMs this way does not sign them. To sign them, use &#39;cosign attest --predicate sbom.json --key &lt;key path&gt;&#39;.&#xA;Uploading SBOM file for [quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40] to [quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:sha256-6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40.sbom] with mediaType [text/spdx+json].&#xA;&#xA;quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg@sha256:8362fb59f6874771b504a945f9866c4603d4539a184fbb9d6742821612275c05&#xA;[2026-04-22T13:54:00,866016323+00:00] End upload-sbom&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-build-image-index-pod | init container: prepare&#xA;2026/04/22 13:54:02 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-build-image-index-pod | init container: place-scripts&#xA;2026/04/22 13:54:03 Decoded script /tekton/scripts/script-0-c45kv&#xA;2026/04/22 13:54:03 Decoded script /tekton/scripts/script-1-9rrz9&#xA;2026/04/22 13:54:03 Decoded script /tekton/scripts/script-2-fjvhb&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-build-image-index-pod | container step-build: &#xA;[2026-04-22T13:54:26,946287288+00:00] Update CA trust&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;Running konflux-build-cli&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] image: quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] images: [quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40]&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] buildah-format: docker&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] always-build-index: false&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] additional-tags: [go-component-opambg-on-pull-request-swzc5-build-image-index]&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] output-manifest-path: /index-build-data/manifest_data.json&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] result-path-image-digest: /tekton/results/IMAGE_DIGEST&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] result-path-image-url: /tekton/results/IMAGE_URL&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] result-path-image-ref: /tekton/results/IMAGE_REF&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;[param] result-path-images: /tekton/results/IMAGES&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;Creating manifest list: quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;buildah [stdout] 80a78770719de5cae6cf1e29f01c15a3d8b02431b04bb65fe4f9aff73fd639e8&#34; logger=CliExecutor&#xA;time=&#34;2026-04-22T13:54:29Z&#34; level=info msg=&#34;Skipping image index generation. Returning results for single image.&#34;&#xA;{&#34;image_digest&#34;:&#34;sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#34;,&#34;image_url&#34;:&#34;quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;,&#34;image_ref&#34;:&#34;quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#34;,&#34;images&#34;:&#34;quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#34;}&#xA;pod: go-component-opambg-on-pull-request-swzc5-build-image-index-pod | container step-create-sbom: &#xA;The manifest_data.json file does not exist. Skipping the SBOM creation...&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-build-image-index-pod | container step-upload-sbom: &#xA;[2026-04-22T13:54:30,331943592+00:00] Update CA trust&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;The index.spdx.json file does not exists. Skipping the SBOM upload...&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-clamav-scan-pod | init container: prepare&#xA;2026/04/22 13:54:53 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-clamav-scan-pod | init container: place-scripts&#xA;2026/04/22 13:54:54 Decoded script /tekton/scripts/script-0-gp78x&#xA;2026/04/22 13:54:54 Decoded script /tekton/scripts/script-1-25ncf&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-clamav-scan-pod | container step-extract-and-scan-image: &#xA;Starting clamd ...&#xA;clamd is ready!&#xA;Detecting artifact type for quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40.&#xA;Detected container image. Processing image manifests.&#xA;Running &#34;oc image extract&#34; on image of arch amd64&#xA;Scanning image for arch amd64. This operation may take a while.&#xA;&#xA;----------- SCAN SUMMARY -----------&#xA;Infected files: 0&#xA;Time: 145.607 sec (2 m 25 s)&#xA;Start Date: 2026:04:22 13:55:27&#xA;End Date:   2026:04:22 13:57:52&#xA;Executed-on: Scan was executed on clamsdcan version - ClamAV 1.4.3/27979/Wed Apr 22 06:26:01 2026 Database version: 27979&#xA;[&#xA;&#x9;{&#xA;&#x9;&#x9;&#34;filename&#34;: &#34;/work/logs/clamscan-result-log-amd64.json&#34;,&#xA;&#x9;&#x9;&#34;namespace&#34;: &#34;required_checks&#34;,&#xA;&#x9;&#x9;&#34;successes&#34;: 2&#xA;&#x9;}&#xA;]&#xA;{&#34;timestamp&#34;:&#34;1776866272&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;timestamp&#34;:&#34;1776866272&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;timestamp&#34;:&#34;1776866272&#34;,&#34;namespace&#34;:&#34;required_checks&#34;,&#34;successes&#34;:2,&#34;failures&#34;:0,&#34;warnings&#34;:0,&#34;result&#34;:&#34;SUCCESS&#34;,&#34;note&#34;:&#34;All checks passed successfully&#34;}&#xA;{&#34;image&#34;: {&#34;pullspec&#34;: &#34;quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;, &#34;digests&#34;: [&#34;sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#34;]}}&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-clamav-scan-pod | container step-upload: &#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg&#xA;Attaching to quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;Executing: oras attach --no-tty --registry-config /home/oras/auth.json --artifact-type application/vnd.clamav quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40 clamscan-result-amd64.log:text/vnd.clamav clamscan-ec-test-amd64.json:application/vnd.konflux.test_output+json&#xA;Preparing clamscan-result-amd64.log&#xA;Preparing clamscan-ec-test-amd64.json&#xA;Uploading 6b4bfec3c7a3 clamscan-ec-test-amd64.json&#xA;Exists    44136fa355b3 application/vnd.oci.empty.v1+json&#xA;Uploading fba328bf493b clamscan-result-amd64.log&#xA;Uploaded  fba328bf493b clamscan-result-amd64.log&#xA;Uploaded  6b4bfec3c7a3 clamscan-ec-test-amd64.json&#xA;Uploading bd70e4fd7d18 application/vnd.oci.image.manifest.v1+json&#xA;Uploaded  bd70e4fd7d18 application/vnd.oci.image.manifest.v1+json&#xA;Attached to [registry] quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#xA;Digest: sha256:bd70e4fd7d18403ff357c146fa7f7350223c12ef53e99c84b4e99a2e8cf42b31&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-clone-repository-pod | init container: prepare&#xA;2026/04/22 13:51:21 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-clone-repository-pod | init container: place-scripts&#xA;2026/04/22 13:51:21 Decoded script /tekton/scripts/script-0-4z77h&#xA;2026/04/22 13:51:21 Decoded script /tekton/scripts/script-1-g2nnv&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-clone-repository-pod | container step-clone: &#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;{&#34;level&#34;:&#34;info&#34;,&#34;ts&#34;:1776865886.011179,&#34;caller&#34;:&#34;git/git.go:394&#34;,&#34;msg&#34;:&#34;Retrying operation (attempt 1)&#34;}&#xA;{&#34;level&#34;:&#34;info&#34;,&#34;ts&#34;:1776865886.2054439,&#34;caller&#34;:&#34;git/git.go:223&#34;,&#34;msg&#34;:&#34;Successfully cloned https://github.com/redhat-appstudio-qe/group-snapshot-multi-component @ 4d756f25691014cb931c9ba1a2acbdad0b590a3e (grafted, HEAD) in path /workspace/output/source&#34;}&#xA;{&#34;level&#34;:&#34;info&#34;,&#34;ts&#34;:1776865886.2054956,&#34;caller&#34;:&#34;git/git.go:394&#34;,&#34;msg&#34;:&#34;Retrying operation (attempt 1)&#34;}&#xA;{&#34;level&#34;:&#34;info&#34;,&#34;ts&#34;:1776865886.2287865,&#34;caller&#34;:&#34;git/git.go:277&#34;,&#34;msg&#34;:&#34;Successfully initialized and updated submodules in path /workspace/output/source&#34;}&#xA;Merge option disabled. Using checked-out revision 4d756f25691014cb931c9ba1a2acbdad0b590a3e directly.&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-clone-repository-pod | container step-symlink-check: &#xA;Running symlink check&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-init-pod | init container: prepare&#xA;2026/04/22 13:51:09 Entrypoint initialization&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-init-pod | container step-init: &#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;[param] enable: false&#34;&#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;[param] default-http-proxy: squid.caching.svc.cluster.local:3128&#34;&#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;[param] default-no-proxy: brew.registry.redhat.io,docker.io,gcr.io,ghcr.io,images.paas.redhat.com,mirror.gcr.io,nvcr.io,quay.io,registry-proxy.engineering.redhat.com,registry.access.redhat.com,registry.ci.openshift.org,registry.fedoraproject.org,registry.redhat.io,registry.stage.redhat.io,vault.habana.ai&#34;&#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;[param] http-proxy-result-path: /tekton/results/http-proxy&#34;&#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;[param] no-proxy-result-path: /tekton/results/no-proxy&#34;&#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;Cache proxy is disabled in param or in backend&#34;&#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;[result] HTTP PROXY: &#34;&#xA;time=&#34;2026-04-22T13:51:13Z&#34; level=info msg=&#34;[result] NO PROXY: &#34;&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-push-dockerfile-pod | init container: prepare&#xA;2026/04/22 13:55:50 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-push-dockerfile-pod | init container: working-dir-initializer&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-push-dockerfile-pod | container step-push: &#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] image-url: quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;&#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] image-digest: sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#34;&#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] containerfile: docker/Dockerfile&#34;&#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] context: go-component&#34;&#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] tag-suffix: .dockerfile&#34;&#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] artifact-type: application/vnd.konflux.dockerfile&#34;&#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] source: source&#34;&#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] result-path-image-ref: /tekton/results/IMAGE_REF&#34;&#xA;time=&#34;2026-04-22T13:55:53Z&#34; level=info msg=&#34;[param] alternative-filename: Dockerfile&#34;&#xA;time=&#34;2026-04-22T13:55:54Z&#34; level=info msg=&#34;oras [stdout] quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg@sha256:5ab08358580c75c895f95ec7c7bc938b3017c3907e0b3ae672cd542f267422fd&#34; logger=CliExecutor&#xA;time=&#34;2026-04-22T13:55:54Z&#34; level=info msg=&#34;Containerfile &#39;/workspace/workspace/source/go-component/docker/Dockerfile&#39; is pushed to registry with tag: sha256-6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40.dockerfile&#34;&#xA;{&#34;image_ref&#34;:&#34;quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg@sha256:5ab08358580c75c895f95ec7c7bc938b3017c3907e0b3ae672cd542f267422fd&#34;}&#xA; pod: go-component-opambg-on-pull-request-swzc5-sast-shell-check-pod | init container: prepare&#xA;2026/04/22 13:56:02 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-sast-shell-check-pod | init container: place-scripts&#xA;2026/04/22 13:56:03 Decoded script /tekton/scripts/script-0-rwqrc&#xA;2026/04/22 13:56:03 Decoded script /tekton/scripts/script-1-5btsh&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-sast-shell-check-pod | init container: working-dir-initializer&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-sast-shell-check-pod | container step-sast-shell-check: &#xA;+ source /utils.sh&#xA;++ OPM_RENDER_CACHE=/tmp/konflux-test-opm-cache&#xA;++ DEFAULT_INDEX_IMAGE=registry.redhat.io/redhat/redhat-operator-index&#xA;+ trap &#39;handle_error /tekton/results/TEST_OUTPUT&#39; EXIT&#xA;+ [[ -z &#39;&#39; ]]&#xA;+ PROJECT_NAME=go-component-opambg&#xA;+ echo &#39;INFO: The PROJECT_NAME used is: go-component-opambg&#39;&#xA;INFO: The PROJECT_NAME used is: go-component-opambg&#xA;+ ca_bundle=/mnt/trusted-ca/ca-bundle.crt&#xA;+ &#39;[&#39; -f /mnt/trusted-ca/ca-bundle.crt &#39;]&#39;&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;+ echo &#39;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#39;&#xA;+ cp -vf /mnt/trusted-ca/ca-bundle.crt /etc/pki/ca-trust/source/anchors&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;+ update-ca-trust&#xA;++ rpm -q --queryformat &#39;%{NAME}-%{VERSION}-%{RELEASE}\n&#39; ShellCheck&#xA;+ PACKAGE_VERSION=ShellCheck-0.10.0-3.el9&#xA;+ OUTPUT_FILE=shellcheck-results.json&#xA;+ SOURCE_CODE_DIR=/workspace/workspace/source&#xA;+ declare -a ALL_TARGETS&#xA;+ IFS=,&#xA;+ read -ra TARGET_ARRAY&#xA;+ for d in &#34;${TARGET_ARRAY[@]}&#34;&#xA;+ potential_path=/workspace/workspace/source/.&#xA;++ realpath -m /workspace/workspace/source/.&#xA;+ resolved_path=/workspace/workspace/source&#xA;+ [[ /workspace/workspace/source == \/\w\o\r\k\s\p\a\c\e\/\w\o\r\k\s\p\a\c\e\/\s\o\u\r\c\e* ]]&#xA;+ ALL_TARGETS+=(&#34;$resolved_path&#34;)&#xA;+ &#39;[&#39; -z &#39;&#39; &#39;]&#39;&#xA;+ &#39;[&#39; -r /sys/fs/cgroup/cpu.max &#39;]&#39;&#xA;+ read -r quota period&#xA;+ &#39;[&#39; 800000 &#39;!=&#39; max &#39;]&#39;&#xA;+ &#39;[&#39; -n 100000 &#39;]&#39;&#xA;+ &#39;[&#39; 100000 -gt 0 &#39;]&#39;&#xA;+ export SC_JOBS=8&#xA;+ SC_JOBS=8&#xA;+ echo &#39;INFO: Setting SC_JOBS=8 based on cgroups v2 max for run-shellcheck.sh&#39;&#xA;INFO: Setting SC_JOBS=8 based on cgroups v2 max for run-shellcheck.sh&#xA;+ /usr/share/csmock/scripts/run-shellcheck.sh /workspace/workspace/source&#xA;Looking for shell scripts................ done&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/applypatch-msg.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/commit-msg.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/post-update.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/prepare-commit-msg.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-applypatch.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-commit.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-merge-commit.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-push.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-rebase.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/pre-receive.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/push-to-checkout.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/sendemail-validate.sample&#xA;+ timeout 30 shellcheck --format=json1 --external-sources --source-path=/workspace/workspace/source /workspace/workspace/source/.git/hooks/update.sample&#xA;+ CSGREP_OPTS=(--mode=json --strip-path-prefix=&#34;$SOURCE_CODE_DIR&#34;/ --remove-duplicates --embed-context=3 --set-scan-prop=&#34;ShellCheck:${PACKAGE_VERSION}&#34;)&#xA;+ [[ true == \t\r\u\e ]]&#xA;+ CSGREP_EVENT_FILTER=&#39;\[SC(1020|1035|1054|1066|1068|1073|1080|1083|1099|1113|1115|1127|1128|1143|2043|2050|&#39;&#xA;+ CSGREP_EVENT_FILTER+=&#39;2055|2057|2066|2069|2071|2077|2078|2091|2092|2157|2171|2193|2194|2195|2215|2216|&#39;&#xA;+ CSGREP_EVENT_FILTER+=&#39;2218|2224|2225|2242|2256|2258|2261)\]$&#39;&#xA;+ CSGREP_OPTS+=(--event=&#34;$CSGREP_EVENT_FILTER&#34;)&#xA;+ csgrep --mode=json --strip-path-prefix=/workspace/workspace/source/ --remove-duplicates --embed-context=3 --set-scan-prop=ShellCheck:ShellCheck-0.10.0-3.el9 &#39;--event=\[SC(1020|1035|1054|1066|1068|1073|1080|1083|1099|1113|1115|1127|1128|1143|2043|2050|2055|2057|2066|2069|2071|2077|2078|2091|2092|2157|2171|2193|2194|2195|2215|2216|2218|2224|2225|2242|2256|2258|2261)\]$&#39; ./shellcheck-results/empty.json ./shellcheck-results/sc-105.json ./shellcheck-results/sc-111.json ./shellcheck-results/sc-114.json ./shellcheck-results/sc-117.json ./shellcheck-results/sc-70.json ./shellcheck-results/sc-73.json ./shellcheck-results/sc-74.json ./shellcheck-results/sc-76.json ./shellcheck-results/sc-79.json ./shellcheck-results/sc-82.json&#xA;+ [[ SITE_DEFAULT == \S\I\T\E\_\D\E\F\A\U\L\T ]]&#xA;+ KFP_GIT_URL=https://gitlab.cee.redhat.com/osh/known-false-positives.git&#xA;+ PROBE_URL=https://gitlab.cee.redhat.com/osh/known-false-positives&#xA;+ KFP_DIR=known-false-positives&#xA;+ KFP_CLONED=0&#xA;+ mkdir known-false-positives&#xA;+ [[ -n https://gitlab.cee.redhat.com/osh/known-false-positives.git ]]&#xA;INFO: Probing https://gitlab.cee.redhat.com/osh/known-false-positives... + echo -n &#39;INFO: Probing https://gitlab.cee.redhat.com/osh/known-false-positives... &#39;&#xA;+ curl --fail --head --max-time 60 --no-progress-meter https://gitlab.cee.redhat.com/osh/known-false-positives&#xA;++ head -1&#xA;curl: (6) Could not resolve host: gitlab.cee.redhat.com&#xA;+ [[ 0 -eq 0 ]]&#xA;WARN: Failed to clone known-false-positives at https://gitlab.cee.redhat.com/osh/known-false-positives.git, scan results will not be filtered&#xA;+ echo &#39;WARN: Failed to clone known-false-positives at https://gitlab.cee.redhat.com/osh/known-false-positives.git, scan results will not be filtered&#39;&#xA;ShellCheck results have been saved to shellcheck-results.json&#xA;+ echo &#39;ShellCheck results have been saved to shellcheck-results.json&#39;&#xA;+ csgrep --mode=evtstat shellcheck-results.json&#xA;+ csgrep --mode=sarif shellcheck-results.json&#xA;+ TEST_OUTPUT=&#xA;+ parse_test_output sast-shell-check sarif shellcheck-results.sarif&#xA;+ TEST_NAME=sast-shell-check&#xA;+ TEST_RESULT_FORMAT=sarif&#xA;+ TEST_RESULT_FILE=shellcheck-results.sarif&#xA;+ &#39;[&#39; -z sast-shell-check &#39;]&#39;&#xA;+ &#39;[&#39; -z sarif &#39;]&#39;&#xA;+ &#39;[&#39; -z shellcheck-results.sarif &#39;]&#39;&#xA;+ &#39;[&#39; &#39;!&#39; -f shellcheck-results.sarif &#39;]&#39;&#xA;+ &#39;[&#39; sarif = sarif &#39;]&#39;&#xA;+++ jq -rce &#39;(if (.runs[].results | length &gt; 0) then &#34;FAILURE&#34; else &#34;SUCCESS&#34; end)&#39; shellcheck-results.sarif&#xA;+++ jq -rce &#39;(.runs[].results | length)&#39; shellcheck-results.sarif&#xA;++ make_result_json -r SUCCESS -f 0&#xA;++ local RESULT=&#xA;++ local SUCCESSES=0&#xA;++ local FAILURES=0&#xA;++ local WARNINGS=0&#xA;++ local &#39;NOTE=For details, check Tekton task log.&#39;&#xA;++ local NAMESPACE=default&#xA;++ local OUTPUT&#xA;++ local OPTIND opt&#xA;++ getopts :r:s:f:w:t:n: opt&#xA;++ case &#34;${opt}&#34; in&#xA;++ RESULT=SUCCESS&#xA;++ getopts :r:s:f:w:t:n: opt&#xA;++ case &#34;${opt}&#34; in&#xA;++ FAILURES=0&#xA;++ getopts :r:s:f:w:t:n: opt&#xA;++ shift 4&#xA;++ &#39;[&#39; -z SUCCESS &#39;]&#39;&#xA;++ case &#34;${RESULT}&#34; in&#xA;++++ date -u --iso-8601=seconds&#xA;+++ jq -rce --arg date 2026-04-22T13:56:31+00:00 --arg result SUCCESS --arg note &#39;For details, check Tekton task log.&#39; --arg namespace default --arg successes 0 --arg failures 0 --arg warnings 0 --null-input &#39;{  result: $result,&#xA;        timestamp: $date,&#xA;        note: $note,&#xA;        namespace: $namespace,&#xA;        successes: $successes|tonumber,&#xA;        failures: $failures|tonumber,&#xA;        warnings: $warnings|tonumber&#xA;    }&#39;&#xA;++ OUTPUT=&#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:56:31+00:00&#34;,&#34;note&#34;:&#34;For details, check Tekton task log.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;++ echo &#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:56:31+00:00&#34;,&#34;note&#34;:&#34;For details, check Tekton task log.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;+ TEST_OUTPUT=&#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:56:31+00:00&#34;,&#34;note&#34;:&#34;For details, check Tekton task log.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;++ echo &#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:56:31+00:00&#34;,&#34;note&#34;:&#34;For details, check Tekton task log.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;++ jq .failures&#xA;+ &#39;[&#39; 0 -gt 0 &#39;]&#39;&#xA;+ echo &#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:56:31+00:00&#34;,&#34;note&#34;:&#34;For details, check Tekton task log.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;+ tee /tekton/results/TEST_OUTPUT&#xA;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:56:31+00:00&#34;,&#34;note&#34;:&#34;For details, check Tekton task log.&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;+ handle_error /tekton/results/TEST_OUTPUT&#xA;+ exit_code=0&#xA;+ &#39;[&#39; 0 -ne 0 &#39;]&#39;&#xA;+ exit 0&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-sast-shell-check-pod | container step-upload: &#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg&#xA;Attaching to quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;Executing: oras attach --no-tty --registry-config /home/oras/auth.json --artifact-type application/sarif+json quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40 shellcheck-results.sarif:application/sarif+json&#xA;Preparing shellcheck-results.sarif&#xA;Exists    44136fa355b3 application/vnd.oci.empty.v1+json&#xA;Uploading 3b606a9dd3a1 shellcheck-results.sarif&#xA;Uploaded  3b606a9dd3a1 shellcheck-results.sarif&#xA;Uploading edffcbe0534d application/vnd.oci.image.manifest.v1+json&#xA;Uploaded  edffcbe0534d application/vnd.oci.image.manifest.v1+json&#xA;Attached to [registry] quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#xA;Digest: sha256:edffcbe0534d0ee5d0e146eb34f7226ab5c7a5ed155ac508f44bfb2e7b279827&#xA;No excluded-findings.json exists. Skipping upload.&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-sast-snyk-check-pod | init container: prepare&#xA;2026/04/22 13:56:02 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-sast-snyk-check-pod | init container: place-scripts&#xA;2026/04/22 13:56:03 Decoded script /tekton/scripts/script-0-t4vnl&#xA;2026/04/22 13:56:03 Decoded script /tekton/scripts/script-1-dnvrb&#xA;&#xA; pod: go-component-opambg-on-pull-request-swzc5-sast-snyk-check-pod | init container: working-dir-initializer&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-sast-snyk-check-pod | container step-sast-snyk-check: &#xA;INFO: The PROJECT_NAME used is: go-component-opambg&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;{&#34;result&#34;:&#34;SKIPPED&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:56:31+00:00&#34;,&#34;note&#34;:&#34;Task sast-snyk-check skipped: If you wish to use the Snyk code SAST task, please create a secret name snyk-secret with the key &#39;snyk_token&#39; containing the Snyk token by following the steps given [here](https://konflux-ci.dev/docs/testing/build/snyk/)&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;&#xA;pod: go-component-opambg-on-pull-request-swzc5-sast-snyk-check-pod | container step-upload: &#xA;No sast_snyk_check_out.sarif exists. Skipping upload.&#xA;No excluded-findings.json exists. Skipping upload.&#xA;&#xA; pod: go-component-opambg-on-pull1f555b19b24993b3aa0a16d2c70dade1-pod | init container: prepare&#xA;2026/04/22 13:55:50 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pull1f555b19b24993b3aa0a16d2c70dade1-pod | init container: place-scripts&#xA;2026/04/22 13:55:51 Decoded script /tekton/scripts/script-0-2bwbc&#xA;2026/04/22 13:55:51 Decoded script /tekton/scripts/script-1-n88w8&#xA;&#xA; pod: go-component-opambg-on-pull1f555b19b24993b3aa0a16d2c70dade1-pod | init container: working-dir-initializer&#xA;&#xA;pod: go-component-opambg-on-pull1f555b19b24993b3aa0a16d2c70dade1-pod | container step-sast-unicode-check: &#xA;+ . /utils.sh&#xA;++ OPM_RENDER_CACHE=/tmp/konflux-test-opm-cache&#xA;++ DEFAULT_INDEX_IMAGE=registry.redhat.io/redhat/redhat-operator-index&#xA;+ trap &#39;handle_error /tekton/results/TEST_OUTPUT&#39; EXIT&#xA;+ [[ -z &#39;&#39; ]]&#xA;+ PROJECT_NAME=go-component-opambg&#xA;+ echo &#39;INFO: The PROJECT_NAME used is: go-component-opambg&#39;&#xA;INFO: The PROJECT_NAME used is: go-component-opambg&#xA;+ ca_bundle=/mnt/trusted-ca/ca-bundle.crt&#xA;+ &#39;[&#39; -f /mnt/trusted-ca/ca-bundle.crt &#39;]&#39;&#xA;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#xA;+ echo &#39;INFO: Using mounted CA bundle: /mnt/trusted-ca/ca-bundle.crt&#39;&#xA;+ cp -vf /mnt/trusted-ca/ca-bundle.crt /etc/pki/ca-trust/source/anchors&#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;+ update-ca-trust&#xA;+ SCAN_PROP=https://github.com/siddhesh/find-unicode-control.git#c2accbfbba7553a8bc1ebd97089ae08ad8347e58&#xA;+ FUC_EXIT_CODE=0&#xA;+ LANG=en_US.utf8&#xA;+ find_unicode_control.py -p bidi -v -d -t /workspace/workspace/source&#xA;+ [[ 0 -ne 0 ]]&#xA;+ sed -i raw_sast_unicode_check_out.txt -E -e &#39;s|(.*:[0-9]+)(.*)|\1: warning:\2|&#39; -e &#39;s|^|Error: UNICONTROL_WARNING:\n|&#39;&#xA;+ CSGERP_OPTS=(--mode=json --remove-duplicates --embed-context=3 --set-scan-prop=&#34;${SCAN_PROP}&#34; --strip-path-prefix=&#34;${SOURCE_CODE_DIR}&#34;/source/)&#xA;+ csgrep --mode=json --remove-duplicates --embed-context=3 --set-scan-prop=https://github.com/siddhesh/find-unicode-control.git#c2accbfbba7553a8bc1ebd97089ae08ad8347e58 --strip-path-prefix=/workspace/workspace/source/ raw_sast_unicode_check_out.txt&#xA;+ csgrep --mode=evtstat processed_sast_unicode_check_out.json&#xA;+ [[ SITE_DEFAULT == \S\I\T\E\_\D\E\F\A\U\L\T ]]&#xA;+ KFP_GIT_URL=https://gitlab.cee.redhat.com/osh/known-false-positives.git&#xA;+ PROBE_URL=https://gitlab.cee.redhat.com/osh/known-false-positives&#xA;+ KFP_DIR=known-false-positives&#xA;+ KFP_CLONED=0&#xA;+ mkdir known-false-positives&#xA;+ [[ -n https://gitlab.cee.redhat.com/osh/known-false-positives.git ]]&#xA;INFO: Probing https://gitlab.cee.redhat.com/osh/known-false-positives... + echo -n &#39;INFO: Probing https://gitlab.cee.redhat.com/osh/known-false-positives... &#39;&#xA;+ curl --fail --head --max-time 60 --no-progress-meter https://gitlab.cee.redhat.com/osh/known-false-positives&#xA;++ head -1&#xA;curl: (6) Could not resolve host: gitlab.cee.redhat.com&#xA;+ [[ 0 -eq 0 ]]&#xA;WARN: Failed to clone known-false-positives at https://gitlab.cee.redhat.com/osh/known-false-positives.git, scan results will not be filtered&#xA;+ echo &#39;WARN: Failed to clone known-false-positives at https://gitlab.cee.redhat.com/osh/known-false-positives.git, scan results will not be filtered&#39;&#xA;+ mv processed_sast_unicode_check_out.json sast_unicode_check_out.json&#xA;+ csgrep --mode=sarif sast_unicode_check_out.json&#xA;+ [[ 0 -eq 0 ]]&#xA;+ note=&#39;Task sast-unicode-check success: No finding was detected&#39;&#xA;++ make_result_json -r SUCCESS -t &#39;Task sast-unicode-check success: No finding was detected&#39;&#xA;++ local RESULT=&#xA;++ local SUCCESSES=0&#xA;++ local FAILURES=0&#xA;++ local WARNINGS=0&#xA;++ local &#39;NOTE=For details, check Tekton task log.&#39;&#xA;++ local NAMESPACE=default&#xA;++ local OUTPUT&#xA;++ local OPTIND opt&#xA;++ getopts :r:s:f:w:t:n: opt&#xA;++ case &#34;${opt}&#34; in&#xA;++ RESULT=SUCCESS&#xA;++ getopts :r:s:f:w:t:n: opt&#xA;++ case &#34;${opt}&#34; in&#xA;++ NOTE=&#39;Task sast-unicode-check success: No finding was detected&#39;&#xA;++ getopts :r:s:f:w:t:n: opt&#xA;++ shift 4&#xA;++ &#39;[&#39; -z SUCCESS &#39;]&#39;&#xA;++ case &#34;${RESULT}&#34; in&#xA;++++ date -u --iso-8601=seconds&#xA;+++ jq -rce --arg date 2026-04-22T13:55:59+00:00 --arg result SUCCESS --arg note &#39;Task sast-unicode-check success: No finding was detected&#39; --arg namespace default --arg successes 0 --arg failures 0 --arg warnings 0 --null-input &#39;{  result: $result,&#xA;        timestamp: $date,&#xA;        note: $note,&#xA;        namespace: $namespace,&#xA;        successes: $successes|tonumber,&#xA;        failures: $failures|tonumber,&#xA;        warnings: $warnings|tonumber&#xA;    }&#39;&#xA;++ OUTPUT=&#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:55:59+00:00&#34;,&#34;note&#34;:&#34;Task sast-unicode-check success: No finding was detected&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;++ echo &#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:55:59+00:00&#34;,&#34;note&#34;:&#34;Task sast-unicode-check success: No finding was detected&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;+ ERROR_OUTPUT=&#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:55:59+00:00&#34;,&#34;note&#34;:&#34;Task sast-unicode-check success: No finding was detected&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;+ tee /tekton/results/TEST_OUTPUT&#xA;+ echo &#39;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:55:59+00:00&#34;,&#34;note&#34;:&#34;Task sast-unicode-check success: No finding was detected&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#39;&#xA;{&#34;result&#34;:&#34;SUCCESS&#34;,&#34;timestamp&#34;:&#34;2026-04-22T13:55:59+00:00&#34;,&#34;note&#34;:&#34;Task sast-unicode-check success: No finding was detected&#34;,&#34;namespace&#34;:&#34;default&#34;,&#34;successes&#34;:0,&#34;failures&#34;:0,&#34;warnings&#34;:0}&#xA;+ handle_error /tekton/results/TEST_OUTPUT&#xA;+ exit_code=0&#xA;+ &#39;[&#39; 0 -ne 0 &#39;]&#39;&#xA;+ exit 0&#xA;&#xA;pod: go-component-opambg-on-pull1f555b19b24993b3aa0a16d2c70dade1-pod | container step-upload: &#xA;Selecting auth&#xA;Using token for quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg&#xA;Attaching to quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;Executing: oras attach --no-tty --registry-config /home/oras/auth.json --artifact-type application/sarif+json quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40 sast_unicode_check_out.sarif:application/sarif+json&#xA;Preparing sast_unicode_check_out.sarif&#xA;Uploading 1da9b99b8b41 sast_unicode_check_out.sarif&#xA;Exists    44136fa355b3 application/vnd.oci.empty.v1+json&#xA;Uploaded  1da9b99b8b41 sast_unicode_check_out.sarif&#xA;Uploading 35bb0c2d0736 application/vnd.oci.image.manifest.v1+json&#xA;Uploaded  35bb0c2d0736 application/vnd.oci.image.manifest.v1+json&#xA;Attached to [registry] quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e@sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40&#xA;Digest: sha256:35bb0c2d07365a324e0089a71cfff5fe6c212212b16b82ab6682d2b6b662f8a4&#xA;No excluded-findings.json exists. Skipping upload.&#xA;&#xA; pod: go-component-opambg-on-pullc0db0bde478bcb5d829a136c342a5790-pod | init container: prepare&#xA;2026/04/22 13:54:39 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pullc0db0bde478bcb5d829a136c342a5790-pod | init container: place-scripts&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-0-6nfr8&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-1-fns7d&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-2-d2qv5&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-3-7n284&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-4-ktq5z&#xA;2026/04/22 13:54:39 Decoded script /tekton/scripts/script-5-zb76n&#xA;&#xA;pod: go-component-opambg-on-pullc0db0bde478bcb5d829a136c342a5790-pod | container step-introspect: &#xA;Artifact type will be determined by introspection.&#xA;Checking the media type of the OCI artifact...&#xA;[retry] executing: skopeo inspect --raw --retry-times 3 docker://quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;The media type of the OCI artifact is application/vnd.docker.distribution.manifest.v2+json.&#xA;Looking for image labels that indicate this might be an operator bundle...&#xA;[retry] executing: skopeo inspect --retry-times 3 docker://quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;Found 0 matching labels.&#xA;Expecting 3 or more to identify this image as an operator bundle.&#xA;Introspection concludes that this artifact is of type &#34;application&#34;.&#xA;&#xA;pod: go-component-opambg-on-pullc0db0bde478bcb5d829a136c342a5790-pod | container step-generate-container-auth: &#xA;Selecting auth for quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;Using token for quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg&#xA;Auth json written to &#34;/auth/auth.json&#34;.&#xA;&#xA;pod: go-component-opambg-on-pullc0db0bde478bcb5d829a136c342a5790-pod | container step-set-skip-for-bundles: &#xA;2026/04/22 13:56:19 INFO Step was skipped due to when expressions were evaluated to false.&#xA;&#xA;pod: go-component-opambg-on-pullc0db0bde478bcb5d829a136c342a5790-pod | container step-app-check: &#xA;time=&#34;2026-04-22T13:56:19Z&#34; level=info msg=&#34;certification library version&#34; version=&#34;1.17.1 &lt;commit: f7de82ae1c76e6c10ea94967d6b6a66f96248cbe&gt;&#34;&#xA;time=&#34;2026-04-22T13:56:19Z&#34; level=info msg=&#34;running checks for quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e for platform amd64&#34;&#xA;time=&#34;2026-04-22T13:56:19Z&#34; level=info msg=&#34;target image&#34; image=&#34;quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;&#xA;time=&#34;2026-04-22T13:56:44Z&#34; level=info msg=&#34;warning: licenses directory does not exist or all of its children are empty directories: error when checking for /licenses: stat /tmp/preflight-1084243737/fs/licenses: no such file or directory&#34; check=HasLicense&#xA;time=&#34;2026-04-22T13:56:44Z&#34; level=info msg=&#34;check completed&#34; check=HasLicense result=FAILED&#xA;time=&#34;2026-04-22T13:56:44Z&#34; level=info msg=&#34;check completed&#34; check=HasUniqueTag result=PASSED&#xA;time=&#34;2026-04-22T13:56:44Z&#34; level=info msg=&#34;check completed&#34; check=LayerCountAcceptable result=PASSED&#xA;time=&#34;2026-04-22T13:56:44Z&#34; level=info msg=&#34;check completed&#34; check=HasNoProhibitedPackages result=PASSED&#xA;time=&#34;2026-04-22T13:56:44Z&#34; level=info msg=&#34;check completed&#34; check=HasRequiredLabel result=PASSED&#xA;time=&#34;2026-04-22T13:56:44Z&#34; level=info msg=&#34;USER 1001 specified that is non-root&#34; check=RunAsNonRoot&#xA;time=&#34;2026-04-22T13:56:44Z&#34; level=info msg=&#34;check completed&#34; check=RunAsNonRoot result=PASSED&#xA;time=&#34;2026-04-22T13:57:14Z&#34; level=info msg=&#34;check completed&#34; check=HasModifiedFiles result=PASSED&#xA;time=&#34;2026-04-22T13:57:14Z&#34; level=info msg=&#34;check completed&#34; check=BasedOnUbi result=PASSED&#xA;time=&#34;2026-04-22T13:57:14Z&#34; level=info msg=&#34;This image&#39;s tag on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e will be paired with digest sha256:6fafff3b8768a8e2022e67dd9a08fed617cfcbfbbbb5bbb7736406fa9f07bc40 once this image has been published in accordance with Red Hat Certification policy. You may then add or remove any supplemental tags through your Red Hat Connect portal as you see fit.&#34;&#xA;{&#xA;    &#34;image&#34;: &#34;quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#34;,&#xA;    &#34;passed&#34;: false,&#xA;    &#34;test_library&#34;: {&#xA;        &#34;name&#34;: &#34;github.com/redhat-openshift-ecosystem/openshift-preflight&#34;,&#xA;        &#34;version&#34;: &#34;1.17.1&#34;,&#xA;        &#34;commit&#34;: &#34;f7de82ae1c76e6c10ea94967d6b6a66f96248cbe&#34;&#xA;    },&#xA;    &#34;results&#34;: {&#xA;        &#34;passed&#34;: [&#xA;            {&#xA;                &#34;name&#34;: &#34;HasUniqueTag&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if container has a tag other than &#39;latest&#39;, so that the image can be uniquely identified.&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;LayerCountAcceptable&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if container has less than 40 layers.  Too many layers within the container images can degrade container performance.&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;HasNoProhibitedPackages&#34;,&#xA;                &#34;elapsed_time&#34;: 121,&#xA;                &#34;description&#34;: &#34;Checks to ensure that the image in use does not include prohibited packages, such as Red Hat Enterprise Linux (RHEL) kernel packages.&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;HasRequiredLabel&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if the required labels (name, vendor, version, release, summary, description, maintainer) are present in the container metadata&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;RunAsNonRoot&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if container runs as the root user because a container that does not specify a non-root user will fail the automatic certification, and will be subject to a manual review before the container can be approved for publication&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;HasModifiedFiles&#34;,&#xA;                &#34;elapsed_time&#34;: 29308,&#xA;                &#34;description&#34;: &#34;Checks that no files installed via RPM in the base Red Hat layer have been modified&#34;&#xA;            },&#xA;            {&#xA;                &#34;name&#34;: &#34;BasedOnUbi&#34;,&#xA;                &#34;elapsed_time&#34;: 186,&#xA;                &#34;description&#34;: &#34;Checking if the container&#39;s base image is based upon the Red Hat Universal Base Image (UBI)&#34;&#xA;            }&#xA;        ],&#xA;        &#34;failed&#34;: [&#xA;            {&#xA;                &#34;name&#34;: &#34;HasLicense&#34;,&#xA;                &#34;elapsed_time&#34;: 0,&#xA;                &#34;description&#34;: &#34;Checking if terms and conditions applicable to the software including open source licensing information are present. The license must be at /licenses&#34;,&#xA;                &#34;help&#34;: &#34;Check HasLicense encountered an error. Please review the preflight.log file for more information.&#34;,&#xA;                &#34;suggestion&#34;: &#34;Create a directory named /licenses and include all relevant licensing and/or terms and conditions as text file(s) in that directory.&#34;,&#xA;                &#34;knowledgebase_url&#34;: &#34;https://access.redhat.com/documentation/en-us/red_hat_software_certification/2024/html-single/red_hat_openshift_software_certification_policy_guide/index#assembly-requirements-for-container-images_openshift-sw-cert-policy-introduction&#34;,&#xA;                &#34;check_url&#34;: &#34;https://access.redhat.com/documentation/en-us/red_hat_software_certification/2024/html-single/red_hat_openshift_software_certification_policy_guide/index#assembly-requirements-for-container-images_openshift-sw-cert-policy-introduction&#34;&#xA;            }&#xA;        ],&#xA;        &#34;errors&#34;: []&#xA;    }&#xA;}&#xA;time=&#34;2026-04-22T13:57:14Z&#34; level=info msg=&#34;Preflight result: FAILED&#34;&#xA;&#xA;pod: go-component-opambg-on-pullc0db0bde478bcb5d829a136c342a5790-pod | container step-app-set-outcome: &#xA;{&#34;result&#34;:&#34;FAILURE&#34;,&#34;timestamp&#34;:&#34;1776866234&#34;,&#34;note&#34;:&#34;Task preflight is a FAILURE: Refer to Tekton task logs for more information&#34;,&#34;successes&#34;:7,&#34;failures&#34;:1,&#34;warnings&#34;:0}[retry] executing: skopeo inspect --raw --retry-times 3 docker://quay.io/redhat-appstudio-qe/group-psuf/go-component-opambg:on-pr-4d756f25691014cb931c9ba1a2acbdad0b590a3e&#xA;&#xA;pod: go-component-opambg-on-pullc0db0bde478bcb5d829a136c342a5790-pod | container step-final-outcome: &#xA;+ [[ ! -f /mount/konflux.results.json ]]&#xA;+ tee /tekton/steps/step-final-outcome/results/test-output&#xA;{&#34;result&#34;:&#34;FAILURE&#34;,&#34;timestamp&#34;:&#34;1776866234&#34;,&#34;note&#34;:&#34;Task preflight is a FAILURE: Refer to Tekton task logs for more information&#34;,&#34;successes&#34;:7,&#34;failures&#34;:1,&#34;warnings&#34;:0}&#xA; pod: go-component-opambg-on-pulld4713d98cf1b27d9b1dbdd557154aa55-pod | init container: prepare&#xA;2026/04/22 13:51:28 Entrypoint initialization&#xA;&#xA; pod: go-component-opambg-on-pulld4713d98cf1b27d9b1dbdd557154aa55-pod | init container: place-scripts&#xA;2026/04/22 13:51:29 Decoded script /tekton/scripts/script-0-csw5r&#xA;&#xA;pod: go-component-opambg-on-pulld4713d98cf1b27d9b1dbdd557154aa55-pod | container step-prefetch-dependencies: &#xA;&#39;/mnt/trusted-ca/ca-bundle.crt&#39; -&gt; &#39;/etc/pki/ca-trust/source/anchors/ca-bundle.crt&#39;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=debug msg=&#34;Starting prefetch-dependencies&#34;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;Using in-cluster config&#34; logger=KubeClient&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;Not using package registry proxy because allow-package-registry-proxy is not set to `true` on the cluster level&#34; logger=PrefetchDependencies&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;[param] source-dir: /workspace/source/source&#34;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;[param] output-dir: /workspace/source/cachi2/output&#34;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;[param] sbom-format: spdx&#34;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;[param] mode: strict&#34;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;[param] output-dir-mount-point: /cachi2/output&#34;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;[param] env-files: [/workspace/source/cachi2/cachi2.env /workspace/source/cachi2/prefetch.env /workspace/source/cachi2/prefetch-env.json]&#34;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;[param] git-auth-directory: /workspace/git-basic-auth&#34;&#xA;time=&#34;2026-04-22T13:51:42Z&#34; level=info msg=&#34;hermeto [stdout] hermeto 0.50.1&#34; logger=CliExecutor&#xA;time=&#34;2026-04-22T13:51:43Z&#34; level=warning msg=&#34;No input provided; skipping prefetch-dependencies&#34; logger=PrefetchDependencies&#xA;time=&#34;2026-04-22T13:51:43Z&#34; level=debug msg=&#34;Finished prefetch-dependencies&#34;&#xA;New PipelineRun go-component-opambg-on-pull-request-nkpx9 found after retrigger for component group-psuf/go-component-opambg&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 found for Component group-psuf/go-component-opambg&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Running&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Completed&#xA;&lt; Exit [It] should lead to build PipelineRunA finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:231 @ 04/22/26 14:03:40.453 (12m34.814s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.453&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.453 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component A should lead to a PaC PR creation for componentA go-component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.375889316">
              <system-err>&gt; Enter [It] should lead to a PaC PR creation for componentA go-component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:236 @ 04/22/26 14:03:40.454&#xA;&lt; Exit [It] should lead to a PaC PR creation for componentA go-component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:236 @ 04/22/26 14:03:40.83 (376ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.83&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.83 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLRA is finished successfully checks if the Snapshot is created [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.007241443">
              <system-err>&gt; Enter [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:258 @ 04/22/26 14:03:40.83&#xA;&lt; Exit [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:258 @ 04/22/26 14:03:40.837 (7ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.837&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.837 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLRA is finished successfully should find the related Integration PipelineRuns [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.007614641">
              <system-err>&gt; Enter [It] should find the related Integration PipelineRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:263 @ 04/22/26 14:03:40.838&#xA;&lt; Exit [It] should find the related Integration PipelineRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:263 @ 04/22/26 14:03:40.845 (7ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.845&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.845 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLRA is finished successfully integration pipeline should end up with success [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.006998549">
              <system-err>&gt; Enter [It] integration pipeline should end up with success - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:270 @ 04/22/26 14:03:40.846&#xA;PipelineRun integration-resolver-pipelinerun-jw6gf reason: Succeeded&#xA;&lt; Exit [It] integration pipeline should end up with success - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:270 @ 04/22/26 14:03:40.853 (7ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.853&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:40.853 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Snapshot testing is completed successfully should merge the init PaC PR successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="2.238661058">
              <system-err>&gt; Enter [It] should merge the init PaC PR successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:277 @ 04/22/26 14:03:40.853&#xA;merged result sha: 3dacf4133518194271ce4c8150e3237ec84b637f for PR #21270&#xA;&lt; Exit [It] should merge the init PaC PR successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:277 @ 04/22/26 14:03:43.091 (2.238s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:43.092&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:43.092 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B creates the Component B successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="10.055352549">
              <system-err>&gt; Enter [It] creates the Component B successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:296 @ 04/22/26 14:03:43.092&#xA;&lt; Exit [It] creates the Component B successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:296 @ 04/22/26 14:03:53.147 (10.055s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:53.147&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:03:53.148 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B triggers a Build PipelineRun for component python-component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="20.022020306">
              <system-err>&gt; Enter [It] triggers a Build PipelineRun for component python-component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:304 @ 04/22/26 14:03:53.148&#xA;Build PipelineRun has not been created yet for the componentB group-psuf/python-component-kwyxcb&#xA;&lt; Exit [It] triggers a Build PipelineRun for component python-component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:304 @ 04/22/26 14:04:13.17 (20.022s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:04:13.17&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:04:13.17 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B does not contain an annotation with a Snapshot Name [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.000263115">
              <system-err>&gt; Enter [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:318 @ 04/22/26 14:04:13.17&#xA;&lt; Exit [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:318 @ 04/22/26 14:04:13.17 (0s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:04:13.17&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:04:13.171 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B should lead to build PipelineRun finishing successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="280.018049113">
              <system-err>&gt; Enter [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:322 @ 04/22/26 14:04:13.171&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng found for Component group-psuf/python-component-kwyxcb&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun python-component-kwyxcb-on-pull-request-j94ng reason: Running&#xA;PipelineRun integration-resolver-pipelinerun-m9vgh reason: Running&#xA;PipelineRun integration-resolver-pipelinerun-m9vgh reason: Succeeded&#xA;&lt; Exit [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:322 @ 04/22/26 14:08:53.189 (4m40.018s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.189&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.189 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component B should lead to a PaC PR creation for component python-component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.364609086">
              <system-err>&gt; Enter [It] should lead to a PaC PR creation for component python-component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:327 @ 04/22/26 14:08:53.189&#xA;&lt; Exit [It] should lead to a PaC PR creation for component python-component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:327 @ 04/22/26 14:08:53.554 (364ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.554&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.554 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully checks if the Snapshot is created [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.006553471">
              <system-err>&gt; Enter [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:349 @ 04/22/26 14:08:53.554&#xA;&lt; Exit [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:349 @ 04/22/26 14:08:53.561 (6ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.561&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.561 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully should find the related Integration PipelineRuns [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.005886417">
              <system-err>&gt; Enter [It] should find the related Integration PipelineRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:354 @ 04/22/26 14:08:53.561&#xA;&lt; Exit [It] should find the related Integration PipelineRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:354 @ 04/22/26 14:08:53.567 (6ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.567&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.567 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully integration pipeline should end up with success [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.005476489">
              <system-err>&gt; Enter [It] integration pipeline should end up with success - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:361 @ 04/22/26 14:08:53.567&#xA;PipelineRun integration-resolver-pipelinerun-m9vgh reason: Succeeded&#xA;&lt; Exit [It] integration pipeline should end up with success - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:361 @ 04/22/26 14:08:53.573 (5ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.573&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:53.573 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Snapshot testing is completed successfully should merge the init PaC PR successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="2.231589007">
              <system-err>&gt; Enter [It] should merge the init PaC PR successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:368 @ 04/22/26 14:08:53.573&#xA;merged result sha: 6c42688f21958a74292ac305a25a62e2e5f57727 for PR #21272&#xA;&lt; Exit [It] should merge the init PaC PR successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:368 @ 04/22/26 14:08:55.805 (2.231s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:55.805&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:08:55.805 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C creates the Component C successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="10.056878103">
              <system-err>&gt; Enter [It] creates the Component C successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:387 @ 04/22/26 14:08:55.805&#xA;&lt; Exit [It] creates the Component C successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:387 @ 04/22/26 14:09:05.862 (10.057s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:09:05.862&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:09:05.862 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C triggers a Build PipelineRun for componentC konflux-test-integration-clone [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="20.026051265">
              <system-err>&gt; Enter [It] triggers a Build PipelineRun for componentC konflux-test-integration-clone - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:395 @ 04/22/26 14:09:05.862&#xA;Build PipelineRun has not been created yet for the componentC group-psuf/konflux-test-integration-clone-fcxekv&#xA;&lt; Exit [It] triggers a Build PipelineRun for componentC konflux-test-integration-clone - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:395 @ 04/22/26 14:09:25.888 (20.026s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:09:25.888&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:09:25.888 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C does not contain an annotation with a Snapshot Name [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.000262395">
              <system-err>&gt; Enter [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:409 @ 04/22/26 14:09:25.889&#xA;&lt; Exit [It] does not contain an annotation with a Snapshot Name - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:409 @ 04/22/26 14:09:25.889 (0s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:09:25.889&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:09:25.889 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C should lead to build PipelineRun finishing successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="220.02095477">
              <system-err>&gt; Enter [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:413 @ 04/22/26 14:09:25.889&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m found for Component group-psuf/konflux-test-integration-clone-fcxekv&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun konflux-test-integration-clone-fcxekv-on-pull-request-62j6m reason: Running&#xA;PipelineRun integration-resolver-pipelinerun-fbjmt reason: Running&#xA;PipelineRun integration-resolver-pipelinerun-fbjmt reason: Succeeded&#xA;&lt; Exit [It] should lead to build PipelineRun finishing successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:413 @ 04/22/26 14:13:05.91 (3m40.021s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:05.91&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:05.91 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when we start creation of a new Component C should lead to a PaC PR creation for componentC konflux-test-integration-clone [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.452423232">
              <system-err>&gt; Enter [It] should lead to a PaC PR creation for componentC konflux-test-integration-clone - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:418 @ 04/22/26 14:13:05.911&#xA;&lt; Exit [It] should lead to a PaC PR creation for componentC konflux-test-integration-clone - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:418 @ 04/22/26 14:13:06.363 (452ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:06.363&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:06.363 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully checks if the Snapshot is created [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.00705456">
              <system-err>&gt; Enter [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:440 @ 04/22/26 14:13:06.364&#xA;&lt; Exit [It] checks if the Snapshot is created - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:440 @ 04/22/26 14:13:06.37 (7ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:06.37&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:06.371 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully should find the related Integration PipelineRuns [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.006717903">
              <system-err>&gt; Enter [It] should find the related Integration PipelineRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:445 @ 04/22/26 14:13:06.371&#xA;&lt; Exit [It] should find the related Integration PipelineRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:445 @ 04/22/26 14:13:06.377 (6ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:06.377&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:06.378 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Build PLR is finished successfully integration pipeline should end up with success [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.005697384">
              <system-err>&gt; Enter [It] integration pipeline should end up with success - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:452 @ 04/22/26 14:13:06.378&#xA;PipelineRun integration-resolver-pipelinerun-fbjmt reason: Succeeded&#xA;&lt; Exit [It] integration pipeline should end up with success - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:452 @ 04/22/26 14:13:06.383 (5ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:06.384&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:06.384 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when the Snapshot testing is completed successfully should merge the init PaC PR successfully [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="2.22141502">
              <system-err>&gt; Enter [It] should merge the init PaC PR successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:459 @ 04/22/26 14:13:06.384&#xA;merged result sha: 4a55a3e976a04e6d5f2fa6e6a040e81593c48265 for PR #8900&#xA;&lt; Exit [It] should merge the init PaC PR successfully - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:459 @ 04/22/26 14:13:08.605 (2.221s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:08.605&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:08.605 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged should make change to the root folder [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="3.396958506">
              <system-err>&gt; Enter [It] should make change to the root folder - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:479 @ 04/22/26 14:13:08.606&#xA;PR #21274 got created with sha b223815deee3928ff67f548c640888925b922110&#xA;&lt; Exit [It] should make change to the root folder - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:479 @ 04/22/26 14:13:12.003 (3.397s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:12.003&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:12.003 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged should make change to the multiple-repo [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="2.46990168">
              <system-err>&gt; Enter [It] should make change to the multiple-repo - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:497 @ 04/22/26 14:13:12.003&#xA;PR #8901 got created with sha 7d2a7487b2bab2f3fce7bd62f8b95e0f342b4449&#xA;&lt; Exit [It] should make change to the multiple-repo - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:497 @ 04/22/26 14:13:14.473 (2.47s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:14.473&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:14.473 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged wait for the last components build to finish [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.035027738">
              <system-err>&gt; Enter [It] wait for the last components build to finish - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:513 @ 04/22/26 14:13:14.474&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 found for Component group-psuf/go-component-opambg&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Completed&#xA;PipelineRun integration-resolver-pipelinerun-m9vgh found for Component group-psuf/python-component-kwyxcb&#xA;PipelineRun integration-resolver-pipelinerun-m9vgh reason: Succeeded&#xA;PipelineRun integration-resolver-pipelinerun-fbjmt found for Component group-psuf/konflux-test-integration-clone-fcxekv&#xA;PipelineRun integration-resolver-pipelinerun-fbjmt reason: Succeeded&#xA;&lt; Exit [It] wait for the last components build to finish - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:513 @ 04/22/26 14:13:14.508 (35ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:14.508&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:14.508 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged wait for all component snapshots to be created with proper PR group annotations [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.00701391">
              <system-err>&gt; Enter [It] wait for all component snapshots to be created with proper PR group annotations - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:521 @ 04/22/26 14:13:14.509&#xA;Component snapshot integ-app-xfep-20260422-135815-000 has PR group annotation: konflux-go-component-opambg&#xA;Component snapshot integ-app-xfep-20260422-140401-000 has PR group annotation: konflux-python-component-kwyxcb&#xA;Component snapshot integ-app-xfep-20260422-140916-000 has PR group annotation: konflux-konflux-test-integration-clone-fcxekv&#xA;All component snapshots are ready with PR group annotations&#xA;&lt; Exit [It] wait for all component snapshots to be created with proper PR group annotations - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:521 @ 04/22/26 14:13:14.516 (7ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:14.516&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:13:14.516 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged get all group snapshots and check if pr-group annotation contains all components [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="330.369007202">
              <system-err>&gt; Enter [It] get all group snapshots and check if pr-group annotation contains all components - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:556 @ 04/22/26 14:13:14.516&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 3 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 3 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 4 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 4 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 4 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 4 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 4 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 5 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1 pr-branch-ndnvrv:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 5 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1 pr-branch-ndnvrv:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 5 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1 pr-branch-ndnvrv:1]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 6 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1 pr-branch-ndnvrv:2]&#xA;No group snapshots found yet. Component snapshots may not have been processed by integration service controller yet.&#xA;Attempting to find group snapshots for application integ-app-xfep in namespace group-psuf&#xA;Found 7 component snapshots:&#xA;PR Groups found: map[konflux-go-component-opambg:1 konflux-konflux-test-integration-clone-fcxekv:1 konflux-python-component-kwyxcb:1 pr-branch-ndnvrv:3]&#xA;Found 1 group snapshots!&#xA;  Group Snapshot 0: integ-app-xfep-20260422-141831-623 (type: group)&#xA;    Group Test Info: [{&#34;namespace&#34;:&#34;group-psuf&#34;,&#34;component&#34;:&#34;konflux-test-integration-clone-fcxekv&#34;,&#34;buildPipelineRun&#34;:&#34;konflux-test-integration-clone-fcxekv-on-pull-request-7477j&#34;,&#34;snapshot&#34;:&#34;integ-app-xfep-20260422-141318-000&#34;,&#34;repoUrl&#34;:&#34;https://github.com/redhat-appstudio-qe/konflux-test-integration-clone&#34;,&#34;pullRequestNumber&#34;:&#34;8901&#34;},{&#34;namespace&#34;:&#34;group-psuf&#34;,&#34;component&#34;:&#34;go-component-opambg&#34;,&#34;buildPipelineRun&#34;:&#34;go-component-opambg-on-pull-request-tg5wh&#34;,&#34;snapshot&#34;:&#34;integ-app-xfep-20260422-141316-000&#34;,&#34;repoUrl&#34;:&#34;https://github.com/redhat-appstudio-qe/group-snapshot-multi-component&#34;,&#34;pullRequestNumber&#34;:&#34;21274&#34;},{&#34;namespace&#34;:&#34;group-psuf&#34;,&#34;component&#34;:&#34;python-component-kwyxcb&#34;,&#34;buildPipelineRun&#34;:&#34;python-component-kwyxcb-on-pull-request-bpw5v&#34;,&#34;snapshot&#34;:&#34;integ-app-xfep-20260422-141315-000&#34;,&#34;repoUrl&#34;:&#34;https://github.com/redhat-appstudio-qe/group-snapshot-multi-component&#34;,&#34;pullRequestNumber&#34;:&#34;21274&#34;}]&#xA;Validating group test info annotation: [{&#34;namespace&#34;:&#34;group-psuf&#34;,&#34;component&#34;:&#34;konflux-test-integration-clone-fcxekv&#34;,&#34;buildPipelineRun&#34;:&#34;konflux-test-integration-clone-fcxekv-on-pull-request-7477j&#34;,&#34;snapshot&#34;:&#34;integ-app-xfep-20260422-141318-000&#34;,&#34;repoUrl&#34;:&#34;https://github.com/redhat-appstudio-qe/konflux-test-integration-clone&#34;,&#34;pullRequestNumber&#34;:&#34;8901&#34;},{&#34;namespace&#34;:&#34;group-psuf&#34;,&#34;component&#34;:&#34;go-component-opambg&#34;,&#34;buildPipelineRun&#34;:&#34;go-component-opambg-on-pull-request-tg5wh&#34;,&#34;snapshot&#34;:&#34;integ-app-xfep-20260422-141316-000&#34;,&#34;repoUrl&#34;:&#34;https://github.com/redhat-appstudio-qe/group-snapshot-multi-component&#34;,&#34;pullRequestNumber&#34;:&#34;21274&#34;},{&#34;namespace&#34;:&#34;group-psuf&#34;,&#34;component&#34;:&#34;python-component-kwyxcb&#34;,&#34;buildPipelineRun&#34;:&#34;python-component-kwyxcb-on-pull-request-bpw5v&#34;,&#34;snapshot&#34;:&#34;integ-app-xfep-20260422-141315-000&#34;,&#34;repoUrl&#34;:&#34;https://github.com/redhat-appstudio-qe/group-snapshot-multi-component&#34;,&#34;pullRequestNumber&#34;:&#34;21274&#34;}]&#xA;Group snapshot validation completed successfully&#xA;&lt; Exit [It] get all group snapshots and check if pr-group annotation contains all components - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:556 @ 04/22/26 14:18:44.885 (5m30.369s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:18:44.885&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:18:44.885 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when both the init PaC PRs are merged make sure that group snapshot contains last build pipelinerun for each component [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.042538846">
              <system-err>&gt; Enter [It] make sure that group snapshot contains last build pipelinerun for each component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:635 @ 04/22/26 14:18:44.886&#xA;&lt; Exit [It] make sure that group snapshot contains last build pipelinerun for each component - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:635 @ 04/22/26 14:18:44.928 (42ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:18:44.928&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:18:44.928 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when Older snapshot and integration pipelinerun should be cancelled once new snapshot is created make change to the multiple-repo to trigger a new cycle of testing [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.622024975">
              <system-err>&gt; Enter [It] make change to the multiple-repo to trigger a new cycle of testing - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:648 @ 04/22/26 14:18:44.928&#xA;&lt; Exit [It] make change to the multiple-repo to trigger a new cycle of testing - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:648 @ 04/22/26 14:18:45.55 (622ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:18:45.55&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:18:45.55 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when Older snapshot and integration pipelinerun should be cancelled once new snapshot is created wait for the components A and B build to finish [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.033934034">
              <system-err>&gt; Enter [It] wait for the components A and B build to finish - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:654 @ 04/22/26 14:18:45.551&#xA;Waiting for build pipelineRun to be created for app group-psuf/integ-app-xfep, sha: bb2866eb0cea7e23d46114130972244bd5bb51e2&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 found for Component group-psuf/go-component-opambg&#xA;PipelineRun go-component-opambg-on-pull-request-nkpx9 reason: Completed&#xA;PipelineRun integration-resolver-pipelinerun-bfvbr found for Component group-psuf/python-component-kwyxcb&#xA;PipelineRun integration-resolver-pipelinerun-bfvbr reason: Succeeded&#xA;&lt; Exit [It] wait for the components A and B build to finish - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:654 @ 04/22/26 14:18:45.585 (34ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:18:45.585&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:18:45.585 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when Older snapshot and integration pipelinerun should be cancelled once new snapshot is created get all component snapshots for component A and check if older snapshot has been cancelled [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="420.39129576">
              <system-err>&gt; Enter [It] get all component snapshots for component A and check if older snapshot has been cancelled - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:663 @ 04/22/26 14:18:45.585&#xA;&lt; Exit [It] get all component snapshots for component A and check if older snapshot has been cancelled - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:663 @ 04/22/26 14:25:45.976 (7m0.391s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:25:45.976&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:25:45.976 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when Older snapshot and integration pipelinerun should be cancelled once new snapshot is created get all group snapshots and check if older group snapshot is cancelled [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.014984265">
              <system-err>&gt; Enter [It] get all group snapshots and check if older group snapshot is cancelled - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:690 @ 04/22/26 14:25:45.977&#xA;&lt; Exit [It] get all group snapshots and check if older group snapshot is cancelled - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:690 @ 04/22/26 14:25:45.992 (15ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:25:45.992&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:25:45.992 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when ResolutionRequest is deleted after pipeline completes verifies that ResolutionRequest is deleted after pipeline resolution [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.32949447">
              <system-err>&gt; Enter [It] verifies that ResolutionRequest is deleted after pipeline resolution - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:720 @ 04/22/26 14:25:45.993&#xA;&lt; Exit [It] verifies that ResolutionRequest is deleted after pipeline resolution - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:720 @ 04/22/26 14:25:46.321 (329ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:25:46.322&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:25:46.322 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when ResolutionRequest is deleted after pipeline completes verifies that no orphaned ResolutionRequests remain in namespace after test completion [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="0.266668981">
              <system-err>&gt; Enter [It] verifies that no orphaned ResolutionRequests remain in namespace after test completion - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:740 @ 04/22/26 14:25:46.322&#xA;&lt; Exit [It] verifies that no orphaned ResolutionRequests remain in namespace after test completion - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:740 @ 04/22/26 14:25:46.589 (266ms)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:25:46.589&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:25:46.589 (0s)&#xA;</system-err>
          </testcase>
          <testcase name="[It] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] with status reporting of Integration tests in CheckRuns when IntegrationTestScenario reference to task as pipelinerun resolution trigger pipelinerun for invalid integrationTestScenario by annotating snapshot and verify failing to create integration pipelinerun [integration-service, group-snapshot-creation]" classname="Red Hat App Studio E2E tests" status="passed" time="26.206643769">
              <system-err>&gt; Enter [BeforeAll] when IntegrationTestScenario reference to task as pipelinerun resolution - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:775 @ 04/22/26 14:25:46.589&#xA;&lt; Exit [BeforeAll] when IntegrationTestScenario reference to task as pipelinerun resolution - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:775 @ 04/22/26 14:25:46.644 (55ms)&#xA;&gt; Enter [It] trigger pipelinerun for invalid integrationTestScenario by annotating snapshot and verify failing to create integration pipelinerun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:780 @ 04/22/26 14:25:46.644&#xA;&lt; Exit [It] trigger pipelinerun for invalid integrationTestScenario by annotating snapshot and verify failing to create integration pipelinerun - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:780 @ 04/22/26 14:26:06.697 (20.053s)&#xA;&gt; Enter [AfterAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:149 @ 04/22/26 14:26:06.697&#xA;&lt; Exit [AfterAll] with status reporting of Integration tests in CheckRuns - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:149 @ 04/22/26 14:26:12.796 (6.099s)&#xA;&gt; Enter [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:26:12.796&#xA;&lt; Exit [AfterEach] [integration-service-suite Creation of group snapshots for monorepo and multiple repos] - /tmp/tmp.QN7KPSPXeP/tests/integration-service/group-snapshots-tests.go:50 @ 04/22/26 14:26:12.796 (0s)&#xA;</system-err>
          </testcase>
      </testsuite>
  </testsuites>